PT-2026-43428 · Unknown · Jeecg-Boot

Alices614

·

Published

2026-05-26

·

Updated

2026-05-27

·

CVE-2026-9604

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions JeecgBoot versions prior to 3.9.2
Description Improper access controls exist within the AiragModelController component. A remote attacker can exploit this by manipulating the list/queryById argument, leading to unauthorized access.
Recommendations Update to version 3.9.2.

Exploit

Fix

Improper Access Control

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9604

Affected Products

Jeecg-Boot