CVE-2026-108607
Received Received - Intake

Insecure Direct Object Reference in JeecgBoot Allows Deletion of AI Video Records

Vulnerability report for CVE-2026-108607, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability that allows authenticated users to delete other users' AI video generation records by supplying arbitrary userId values to DELETE /airag/video/deleteVideoRecord. Attackers can obtain record ids from the unchecked GET /airag/video/listByUser endpoint and delete victims' Redis-stored video history entries one record per request.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jeecgboot JeecgBoot 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JeecgBoot through version 3.9.5 has an insecure direct object reference vulnerability. Authenticated users can delete other users' AI video generation records by providing arbitrary userId values to the DELETE /airag/video/deleteVideoRecord endpoint. Attackers can first obtain record IDs from the unprotected GET /airag/video/listByUser endpoint and then delete victims' Redis-stored video history entries one record at a time.

Detection Guidance

To detect this vulnerability, monitor HTTP DELETE requests to /airag/video/deleteVideoRecord with arbitrary userId parameters. Check if authenticated users can delete records not belonging to them by inspecting application logs for unauthorized deletion attempts.

Impact Analysis

This vulnerability allows attackers with valid credentials to delete other users' AI-generated video records. If you use JeecgBoot for AI video generation, your video history could be erased without your consent. This could disrupt workflows, cause data loss, and potentially lead to privacy violations if sensitive video content is removed.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by enabling unauthorized deletion of user data. GDPR requires organizations to ensure data integrity and protect against unauthorized alteration or deletion. HIPAA mandates secure handling of protected health information. Unauthorized deletion of video records may violate these requirements, potentially leading to legal and regulatory penalties.

Mitigation Strategies

Immediately update JeecgBoot to version 3.9.6 or later. Implement strict access controls to ensure users can only delete their own records. Validate userId parameters in DELETE /airag/video/deleteVideoRecord to prevent arbitrary deletions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108607. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart