CVE-2026-108665
Received Received - Intake

JeecgBoot Missing Authorization in AiragPromptsController

Vulnerability report for CVE-2026-108665, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragPromptsController edit handler that allows any authenticated user to modify AI prompt templates. Low-privileged attackers can send PUT or POST requests to /airag/prompts/edit with a template id to overwrite prompt text and model parameters created by administrators or other users.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jeecgboot JeecgBoot 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JeecgBoot through version 3.9.5 has a missing authorization vulnerability in the AiragPromptsController edit handler. This flaw allows any authenticated user, even with low privileges, to modify AI prompt templates by sending PUT or POST requests to /airag/prompts/edit with a template ID. Attackers can overwrite prompt text and model parameters created by administrators or other users.

Detection Guidance

Check for unauthorized modifications to AI prompt templates by monitoring PUT or POST requests to /airag/prompts/edit. Look for requests from low-privileged users that overwrite prompt text or model parameters.

Impact Analysis

An attacker could alter AI prompt templates to manipulate AI responses, leading to incorrect or malicious outputs. This could disrupt business operations, degrade AI service reliability, or be used to spread misinformation. Organizations using JeecgBoot for AI tasks may face data integrity issues or reputational damage.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA if altered AI prompts result in unauthorized data processing or disclosure. GDPR requires data integrity and security, while HIPAA mandates strict access controls. Unauthorized modifications may violate these requirements, risking legal penalties or loss of certification.

Mitigation Strategies

Restrict access to the /airag/prompts/edit endpoint to only authorized users. Implement proper authentication and authorization checks to prevent unauthorized modifications to prompt templates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108665. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart