CVE-2026-108606
Received Received - Intake

JeecgBoot Missing Authorization in AiOcrController

Vulnerability report for CVE-2026-108606, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiOcrController deleteById handler that allows any authenticated user to delete OCR records. Low-privileged attackers can obtain record ids from the unguarded GET /airag/ocr/list endpoint and repeatedly delete every shared OCR prompt record stored in Redis.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jeecgboot JeecgBoot 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JeecgBoot through version 3.9.5 has a missing authorization vulnerability in the AiOcrController deleteById handler. This allows any authenticated user, even with low privileges, to delete OCR records. Attackers can find record IDs from an unprotected GET endpoint and repeatedly delete shared OCR prompt records stored in Redis.

Detection Guidance

Check for unauthorized deletions in Redis logs or application logs. Monitor GET /airag/ocr/list requests for unusual access patterns. Verify if low-privileged users can delete OCR records via AiOcrController.

Impact Analysis

Low-privileged attackers could delete all shared OCR prompt records in Redis, disrupting services that rely on these records. This could lead to data loss, service unavailability, or unauthorized modifications to stored OCR prompts.

Compliance Impact

This vulnerability could lead to unauthorized data deletion or modification, violating integrity and availability requirements in GDPR and HIPAA. It may result in non-compliance due to potential data loss and lack of proper access controls.

Mitigation Strategies

Upgrade JeecgBoot to version 3.9.6 or later. Restrict access to the /airag/ocr/list endpoint. Implement proper authorization checks in AiOcrController deleteById handler. Review and remove unnecessary user permissions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108606. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart