Missing Authorization in JeecgBoot's AiragPromptsController Allows Deletion of AI Prompts
CVE-2026-108666
Key Information:
Badges
What is CVE-2026-108666?
JeecgBoot versions up to 3.9.5 present a security issue in the AiragPromptsController due to a missing authorization check in the deleteBatch handler. This flaw enables authenticated users, including those with low privileges, to delete AI prompt templates created by other users or administrators. Attackers can easily exploit this vulnerability by accessing unprotected prompt IDs via a list endpoint and utilizing them to execute deletion requests, potentially undermining data integrity and user trust.
Affected Version(s)
JeecgBoot 0 <= 3.9.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
