CVE-2026-86228CWE-266CWE-284

JeecgBoot AiragModelController.java exportXls access control

Medium · published September 6, 2026

CVSS v3.1
4.3
EPSS
In the wild
Unconfirmed
What it is

A security vulnerability has been detected in JeecgBoot up to 3.9.3. This vulnerability affects the function exportXls of the file jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/llm/controller/AiragModelController.java. Such manipulation of the argument credential leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 3.9.5 is able to resolve this issue. The name of the patch is a2be896f753936956ee6863b632b8e5a0231345c. You should upgrade the affected component.

The record
Technical detail
CVSS v3.1
4.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C
CVSS v4.0
5.3 · CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
EPSS
Not scored
Weaknesses
CWE-266 · Incorrect Privilege Assignment; CWE-284 · Improper Access Control
Published
2026-09-06T22:30Z
Timeline
  • 06 SEP 22:30Z
    JeecgBoot AiragModelController.java exportXls access control
    cvelistv5