Sceawere
Vulnerability Detail
CVE-2026-108878UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
JeecgBoot Missing Authorization in AiragAppController
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 3h ago
- Vendor
- jeecgboot
- Product
- JeecgBoot
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragAppController queryById handler that allows low-privileged authenticated users to read any AI application configuration. Attackers can enumerate application ids via the unguarded /airag/app/listDict endpoint and query each id to obtain system prompts, memory prompts, model ids, knowledge base ids, and plugin bindings of other users' applications.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-11T15:16:54.733Z",
"pubdate": "2026-10-11T15:16:54.733Z",
"executiveSummary": "JeecgBoot versions through 3.9.5 are susceptible to a missing authorization vulnerability within the AiragAppController component. The vulnerability resides in the queryById handler, which fails to enforce access control checks when retrieving AI application configurations.\nThis security flaw allows authenticated, low-privileged users to bypass authorization constraints and access sensitive configuration data belonging to other users or the system. By leveraging an exposed dictionary lookup endpoint, an attacker can enumerate application IDs and subsequently query those IDs to extract proprietary information.\nThe impact is significant, as it enables unauthorized disclosure of critical system components including AI system prompts, memory prompts, backend model identifiers, associated knowledge base references, and plugin bindings. This exposure leads to a loss of confidentiality regarding the AI application infrastructure. The vulnerability is exploitable by any authenticated user within the system, requiring no special administrative privileges to execute the attack sequence. Remediation is necessary to prevent unauthorized data exfiltration and potential downstream exploitation of the exposed AI configurations.",
"technicalDetails": "The vulnerability exists due to an improper implementation of authorization logic within the AiragAppController handler, specifically the queryById method. In the JeecgBoot architecture, security controls must be strictly enforced at the controller layer to validate that the requester possesses the appropriate ownership or permission context for a given resource ID.\nThe attack flow begins with the discovery of the unauthenticated or insufficiently protected /airag/app/listDict endpoint. This endpoint allows an attacker to list available AI application metadata, effectively providing a mapping of active application identifiers. Once an attacker has compiled a list of these IDs, they can programmatically iterate through them using the vulnerable /airag/app/queryById endpoint.\nBecause the queryById function lacks an authorization check to verify that the requesting user is the rightful owner of the targeted application ID, the backend application processes the request and returns the full configuration object for the specified app. The response payload typically includes sensitive internal configurations such as system prompts, memory retention instructions, specific AI model identifiers, knowledge base database associations, and integrated plugin configurations.\nThis vulnerability is rooted in a failure to perform object-level authorization (BOLA/IDOR variant). The server-side code relies on the input parameter provided by the client without verifying the relationship between the session user and the resource requested. By intercepting these requests or automating the enumeration process, an attacker can scrape the entire repository of AI application settings hosted on the instance. The persistent lack of access control allows for a systematic extraction of data, potentially exposing proprietary prompts and infrastructure details that could facilitate further targeted attacks, such as prompt injection or the abuse of connected knowledge bases and plugins.\nThe vulnerability affects all JeecgBoot versions up to and including 3.9.5. The scope of the issue is restricted to authenticated sessions; however, since low-privileged accounts can trigger the flaw, the impact is broad within multi-tenant or collaborative environments."
}