CVE-2026-108669
Received Received - Intake

JeecgBoot Missing Authorization in AiragKnowledgeController

Vulnerability report for CVE-2026-108669, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the embeddingSearch handler of AiragKnowledgeController that lacks Shiro permission annotations. Low-privileged authenticated attackers can supply knowledge base ids to the GET /airag/knowledge/embedding/search endpoint to read document text chunks from unauthorized knowledge bases.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jeecgboot JeecgBoot 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JeecgBoot through version 3.9.5 has a missing authorization vulnerability in the AiragKnowledgeController's embeddingSearch handler. The GET /airag/knowledge/embedding/search endpoint lacks Shiro permission annotations, allowing low-privileged authenticated attackers to read document text chunks from unauthorized knowledge bases by supplying knowledge base IDs.

Detection Guidance

To detect this vulnerability, monitor HTTP GET requests to the /airag/knowledge/embedding/search endpoint. Check for requests with knowledge base IDs from unauthorized users. Use network logs to identify low-privileged authenticated attackers accessing sensitive document text chunks.

Impact Analysis

Attackers with low privileges could access sensitive document text chunks from knowledge bases they are not authorized to view. This could lead to unauthorized data exposure, information leaks, or potential misuse of confidential information stored in those knowledge bases.

Compliance Impact

This vulnerability could violate compliance requirements under GDPR, HIPAA, or other data protection regulations by enabling unauthorized access to sensitive personal or health information. Organizations may face legal penalties, reputational damage, and loss of trust due to data breaches resulting from this issue.

Mitigation Strategies

Immediately update JeecgBoot to version 3.9.5 or later. Apply Shiro permission annotations to the embeddingSearch handler in AiragKnowledgeController. Restrict access to the /airag/knowledge/embedding/search endpoint using proper authentication and authorization checks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108669. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart