CVE-2026-108664
Received Received - Intake

Missing Authorization in JeecgBoot Allows AI Prompt Template Access

Vulnerability report for CVE-2026-108664, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragPromptsController queryById handler that allows low-privileged authenticated users to read any AI prompt template. Attackers can enumerate ids via the unguarded /airag/prompts/list endpoint and query each one to obtain prompt text, model parameters, and creator details belonging to administrators or other users.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jeecgboot JeecgBoot 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JeecgBoot through version 3.9.5 has a missing authorization vulnerability in the AiragPromptsController queryById handler. This flaw allows low-privileged authenticated users to read any AI prompt template by exploiting an unguarded /airag/prompts/list endpoint. Attackers can enumerate IDs and query each one to access sensitive prompt text, model parameters, and creator details belonging to administrators or other users.

Detection Guidance

Check for unauthorized access to the /airag/prompts/list endpoint by monitoring HTTP requests to this path. Look for repeated queries to /airag/prompts/queryById with varying IDs, which may indicate enumeration attempts.

Impact Analysis

If you are a user of JeecgBoot through 3.9.5, low-privileged attackers could access your AI prompt templates, including sensitive data like model parameters and creator information. This could lead to data leaks, intellectual property theft, or unauthorized access to proprietary AI configurations.

Compliance Impact

This vulnerability could violate compliance with GDPR and HIPAA by exposing sensitive data such as AI prompt templates, which may contain personal or confidential information. Unauthorized access to such data could result in legal penalties, reputational damage, and loss of trust due to non-compliance with data protection regulations.

Mitigation Strategies

Update JeecgBoot to the latest version beyond 3.9.5. Restrict access to the /airag/prompts/list and /airag/prompts/queryById endpoints by implementing proper authentication and authorization checks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108664. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart