Access Control Flaw in JeecgBoot Affects Remote Exploitation Potential
CVE-2026-86228
Key Information:
Badges
What is CVE-2026-86228?
A security vulnerability has been identified in JeecgBoot versions prior to 3.9.4, specifically in the exportXls function of the AiragModelController.java file. This flaw allows for improper access control, enabling attackers to manipulate credentials and gain unauthorized access. The issue can be exploited remotely, making it crucial for users to take proactive measures quickly. The vulnerability has been publicly disclosed, and users are strongly advised to upgrade to version 3.9.5, where the issue has been resolved under patch a2be896f753936956ee6863b632b8e5a0231345c.
Affected Version(s)
JeecgBoot 3.9.0
JeecgBoot 3.9.1
JeecgBoot 3.9.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
