CVE-2026-2822: JeecgBoot Backend airag_app,1,create_by sql injection
A security vulnerability has been detected in JeecgBoot up to 3.9.1. The affected element is an unknown function of the file /jeecgboot/sys/dict/loadDict/airagapp,1,createby of the component Backend Interface. Such manipulation of the argument keyword leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2822?
CVE-2026-2822 is classified as a high severity vulnerability due to the potential for SQL injection.
How do I fix CVE-2026-2822?
To fix CVE-2026-2822, upgrade JeecgBoot to a version later than 3.9.1 to ensure the vulnerability is patched.
What components are affected by CVE-2026-2822?
CVE-2026-2822 affects the Backend Interface of JeecgBoot specifically within the /jeecgboot/sys/dict/loadDict/airag_app,1,create_by function.
Can CVE-2026-2822 be exploited remotely?
Yes, CVE-2026-2822 can be exploited remotely if an attacker can manipulate the vulnerable SQL query.
What are the risks associated with CVE-2026-2822?
The risks associated with CVE-2026-2822 include unauthorized access to the database and potential data leakage or corruption.