CVE-2026-1746: JeecgBoot Online Report API loadDictItemByKeyword sql injection
A vulnerability was identified in JeecgBoot 3.9.0. This vulnerability affects unknown code of the file /JeecgBoot/sys/api/loadDictItemByKeyword of the component Online Report API. Such manipulation of the argument keyword leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1746?
CVE-2026-1746 has a high severity rating due to its potential for SQL injection attacks.
How do I fix CVE-2026-1746?
To fix CVE-2026-1746, you should validate and sanitize user inputs in the loadDictItemByKeyword API endpoint.
What software is affected by CVE-2026-1746?
CVE-2026-1746 affects versions of JeecgBoot, specifically version 3.9.0.
What type of vulnerability is CVE-2026-1746?
CVE-2026-1746 is a SQL injection vulnerability that can lead to unauthorized data access.
Can CVE-2026-1746 be exploited remotely?
Yes, CVE-2026-1746 can be exploited remotely if an attacker can send crafted requests to the affected API.