CVE-2026-108673
Received Received - Intake

JeecgBoot Missing Authorization in AiragPromptsController Export

Vulnerability report for CVE-2026-108673, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragPromptsController exportXls handler that allows any authenticated user to export all AI prompts. Low-privileged attackers can request /airag/prompts/exportXls to download every user's prompts, including prompt content, model ids, and parameters, as an Excel workbook.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jeecgboot JeecgBoot 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JeecgBoot through version 3.9.5 has a missing authorization vulnerability in the AiragPromptsController exportXls handler. This flaw allows any authenticated user, even with low privileges, to export all AI prompts by requesting /airag/prompts/exportXls. The exported data includes prompt content, model IDs, and parameters, all downloaded as an Excel workbook.

Detection Guidance

Check for unauthorized access to /airag/prompts/exportXls endpoint. Monitor logs for repeated requests to this path by authenticated users. Verify if any user has exported an Excel file containing AI prompts without proper authorization.

Impact Analysis

Attackers can steal sensitive AI prompt data, including proprietary models and configurations. This may lead to intellectual property theft, competitive disadvantages, or misuse of AI resources. Organizations using JeecgBoot for AI workflows face data exposure risks.

Compliance Impact

This vulnerability could violate GDPR by exposing personal or sensitive data in prompts. For HIPAA, if prompts contain protected health information, unauthorized access risks non-compliance. Organizations may face fines or legal penalties for failing to protect such data.

Mitigation Strategies

Apply the latest patch or update for JeecgBoot to version 3.9.5 or higher. Restrict access to the /airag/prompts/exportXls endpoint by implementing proper authorization checks. Review and audit user permissions to ensure least privilege access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108673. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart