Insecure Direct Object Reference in JeecgBoot API
CVE-2026-108879
Key Information:
Badges
What is CVE-2026-108879?
The JeecgBoot application, specifically versions up to 3.9.5, is susceptible to an insecure direct object reference (IDOR) vulnerability in the AiragBaseApiController. This flaw allows authenticated users to access other users' AI chat variables by manipulating the username parameter when making POST requests to the /airag/api/getChatVariable endpoint. Attackers can exploit this vulnerability by supplying a target appId, username, and variable name, thereby gaining unauthorized access to sensitive stored chat memory values in Redis. Proper validation and access controls are essential to prevent such unauthorized data leakage.
Affected Version(s)
JeecgBoot 0 <= 3.9.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
