CVE-2026-108667: JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/revertRecycleBin
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to restore deleted AI prompt templates by calling the revertRecycleBin endpoint. Attackers can send PUT requests to /airag/prompts/revertRecycleBin with chosen template ids to clear deleted flags, undoing administrator removals.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A low-privileged authenticated JeecgBoot user can exploit it. The attacker needs network access to the application and the ability to send a PUT request to the affected endpoint.
What capability does exploitation provide?
An attacker can supply chosen AI prompt template IDs to /airag/prompts/revertRecycleBin and clear their deleted flags. This restores prompt templates that an administrator had removed.
How can I determine whether the issue has been exploited?
Review PUT requests to /airag/prompts/revertRecycleBin, particularly requests made by low-privileged accounts. Investigate deleted AI prompt templates that have reappeared without an authorized administrator action.