CVE-2026-108610
Received Received - Intake

JeecgBoot Missing Authorization in AigcWordTemplateController

Vulnerability report for CVE-2026-108610, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AigcWordTemplateController edit handler that allows any authenticated user to modify word templates. Low-privileged attackers can send PUT or POST requests to /airag/word/edit to overwrite shared templates that other users rely on to generate documents.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jeecgboot JeecgBoot 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JeecgBoot through version 3.9.5 has a missing authorization vulnerability in the AigcWordTemplateController edit handler. This allows any authenticated user, even with low privileges, to modify word templates by sending PUT or POST requests to /airag/word/edit. Attackers can overwrite shared templates that other users depend on for document generation.

Detection Guidance

Check for unauthorized PUT or POST requests to /airag/word/edit endpoints. Monitor logs for unusual template modifications by low-privileged users. Use network traffic analysis tools to detect suspicious API calls targeting JeecgBoot instances.

Impact Analysis

Low-privileged attackers could alter shared templates used by other users, potentially causing incorrect or malicious documents to be generated. This could lead to data integrity issues, misinformation, or disruption of document-based workflows relying on these templates.

Compliance Impact

This vulnerability allows low-privileged attackers to modify shared word templates via PUT or POST requests, potentially altering document content. This could lead to unauthorized data changes, impacting integrity and confidentiality requirements under GDPR and HIPAA if sensitive information is involved.

Mitigation Strategies

Apply access controls to restrict PUT/POST requests to /airag/word/edit. Update JeecgBoot to version 3.9.6 or later. Implement input validation for template modifications. Review and audit template changes regularly.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108610. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart