Sceawere
Vulnerability Detail
CVE-2026-108877UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
JeecgBoot Missing Authorization Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 3h ago
- Vendor
- jeecgboot
- Product
- JeecgBoot
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in AiragPromptsController that allows any authenticated user to delete AI prompt templates by calling DELETE /airag/prompts/delete. Low-privileged attackers can obtain template ids from the unguarded GET /airag/prompts/list endpoint and logically delete any user's prompt template, making it unavailable to all users.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-10-11T15:16:54.600Z",
"pubdate": "2026-10-11T15:16:54.600Z",
"executiveSummary": "A missing authorization vulnerability exists within JeecgBoot through version 3.9.5, specifically located inside the AiragPromptsController component. This security flaw enables any authenticated low-privileged user to perform unauthorized administrative actions against the system's AI prompt templates. By exploiting a combination of an unguarded data enumeration endpoint and an unprotected deletion endpoint, an attacker can effectively remove prompt templates belonging to other users across the entire application platform.\nThe primary impact of this vulnerability is the compromise of system availability and data integrity regarding AI prompt configurations. Because the application fails to enforce proper function-level access control checks or object ownership validation upon request processing, low-privileged threat actors can logically delete critical prompt templates, rendering them completely unavailable to legitimate users. This security breakdown undermines multi-tenant isolation and resource management constraints within affected JeecgBoot deployments. Successful exploitation requires valid low-privileged user authentication credentials but demands no special administrative privileges or complex pre-conditions, placing all prompt template data at risk of unauthorized deletion.",
"technicalDetails": "The vulnerability stems from improper access control mechanisms within the AiragPromptsController component of JeecgBoot through version 3.9.5. Specifically, the application architecture exposes functional endpoints associated with AI prompt template management without enforcing strict authorization checks or privilege verification. The root cause lies in the complete absence of role-based access control (RBAC) and object-level ownership checks when handling incoming HTTP requests targeted at sensitive operations.\nThe attack vector relies on a multi-stage exploitation process. In the initial phase, an attacker with minimal system privileges authenticates to the application and targets the endpoint GET /airag/prompts/list. Because this endpoint lacks sufficient access restrictions and authorization boundaries, it acts as an unguarded informational gateway. By issuing a request to GET /airag/prompts/list, the low-privileged user can enumerate existing AI prompt templates and extract sensitive metadata, including unique prompt template ids belonging to arbitrary users across the system.\nIn the subsequent phase, the attacker leverages the harvested template ids to execute unauthorized state-changing operations. The attacker formulates an HTTP request directed at the DELETE /airag/prompts/delete endpoint, passing the targeted template id parameters. When the AiragPromptsController receives this payload, it processes the deletion command directly without verifying whether the requesting authenticated session possesses administrative rights or holds explicit ownership over the target resource.\nUpon processing the request to DELETE /airag/prompts/delete, the system logically deletes the corresponding prompt template from the database or application storage. As a result, the affected AI prompt template becomes instantly unavailable to its rightful owner and all other legitimate system users. This logical deletion disrupts AI-driven workflows and operational features relying on those templates, leading to persistent denial of service and data loss within JeecgBoot installations. The persistent exposure of these endpoints presents a significant security risk to resource integrity."
}