CVE-2026-108669: JeecgBoot through 3.9.5 Missing Authorization via /airag/knowledge/embedding/search
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the embeddingSearch handler of AiragKnowledgeController that lacks Shiro permission annotations. Low-privileged authenticated attackers can supply knowledge base ids to the GET /airag/knowledge/embedding/search endpoint to read document text chunks from unauthorized knowledge bases.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs a low-privileged authenticated JeecgBoot account. They can target the Airag knowledge search endpoint and provide knowledge base IDs for knowledge bases they are not authorized to access.
What information can be exposed?
The issue can expose document text chunks stored in unauthorized knowledge bases through the GET /airag/knowledge/embedding/search endpoint. The provided data does not indicate that the vulnerability permits modification or deletion of data.
How can I determine whether an instance is affected?
JeecgBoot versions through 3.9.5 are identified as affected. The vulnerable handler is embeddingSearch in AiragKnowledgeController, where the endpoint lacks Shiro permission annotations.