CVE-2026-108613: JeecgBoot through 3.9.5 Missing Authorization via /airag/app/release Endpoint
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragAppController release handler that allows any authenticated user to publish or unpublish other users' AI applications. Low-privileged attackers can send POST requests to /airag/app/release to obtain share tokens exposing applications to anonymous chat access, or invalidate existing share links.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated JeecgBoot user, including a low-privileged user, can exploit the affected release handler. No user interaction is required.
What access and endpoint are involved?
Exploitation requires valid authenticated access and the ability to send a POST request to /airag/app/release. The issue affects JeecgBoot through version 3.9.5.
What could an attacker do?
An attacker can publish or unpublish AI applications belonging to other users. Publishing can generate share tokens that expose an application to anonymous chat access, while unpublishing can invalidate existing share links.