Sceawere

Vulnerability Detail

CVE-2026-108879UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

JeecgBoot IDOR Data Disclosure Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
jeecgboot
Product
JeecgBoot
Attack Type
Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability in AiragBaseApiController that allows authenticated users to read other users' AI chat variables via the username parameter. Attackers can send POST requests to /airag/api/getChatVariable with a target appId, username, and variable name to retrieve stored chat memory values from Redis.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-11T15:16:54.870Z",
  "pubdate": "2026-10-11T15:16:54.870Z",
  "executiveSummary": "JeecgBoot versions through 3.9.5 are susceptible to an Insecure Direct Object Reference (IDOR) vulnerability within the AI chat functionality. This flaw resides in the AiragBaseApiController component, which fails to properly validate the relationship between the authenticated user and the requested data.\nThe vulnerability allows an authenticated attacker to bypass authorization controls and programmatically access arbitrary user chat variables stored in Redis. By manipulating the username parameter within a specific API request, an attacker can exfiltrate sensitive chat memory values belonging to other system users.\nThe primary risk is the unauthorized disclosure of private conversational data and potentially sensitive context stored within the AI's memory. This breach of confidentiality impacts any deployment of JeecgBoot utilizing the AiragBaseApiController. Exploitation does not require elevated privileges beyond standard user authentication, making the attack surface significant for multi-user environments. Remediation requires implementing robust server-side access control checks to ensure users can only retrieve variables tied to their own authenticated session identifiers.",
  "technicalDetails": "The vulnerability is located in the AiragBaseApiController, specifically within the logic handling the /airag/api/getChatVariable endpoint. The root cause is a lack of authorization verification when processing incoming requests; the application trusts the user-supplied username parameter without cross-referencing it against the authenticated user's security context or token claims.\nWhen a user initiates a POST request to /airag/api/getChatVariable, the backend retrieves data from an underlying Redis instance where chat variables are indexed by keys including appId, username, and variable name. Because the application logic fails to perform an ownership check, the request handler directly queries the Redis store using the parameters provided in the POST body.\nAn attacker can exploit this by intercepting or crafting a POST request containing the target's username and the desired variable name. The attack flow proceeds as follows: 1) The attacker authenticates as a standard user. 2) The attacker identifies a target username and the specific AI chat variable they wish to access. 3) The attacker sends a crafted POST request to /airag/api/getChatVariable including the target 'username' and 'appId' in the JSON body. 4) The server processes the request, fails to validate that the 'username' matches the authenticated user, and proceeds to retrieve the requested data from Redis. 5) The server returns the contents of the memory variable to the attacker's response.\nThis vulnerability is classified as an IDOR (Insecure Direct Object Reference). The impact is significant as it allows for the mass exfiltration of sensitive information stored in chat history or AI memory buffers. Since the variables are stored in Redis, the performance impact of exploitation is negligible for the attacker, enabling rapid data scraping if the attacker possesses a list of valid usernames. The vulnerability affects all versions of JeecgBoot through 3.9.5 that have the AI module enabled."
}
CVE-2026-108879: JeecgBoot IDOR Data Disclosure Vulnerability (MEDIUM Severity, CVSS: 4.3) | Sceawere