Junglewise Threat Intelligence

CVE-2026-86228: JeecgBoot AiragModelController improper access control in exportXls

CVE-2026-86228 · Severity: medium · CVSS 4.3 · Published 2026-09-06

Executive brief

JeecgBoot is an enterprise-grade low-code platform used to rapidly generate enterprise applications with minimal coding. A flaw in the AiragModelController's exportXls function allows attackers to manipulate credential parameters, bypassing access controls and potentially accessing or exporting sensitive data without proper authorization.

Technical details

The vulnerability is an improper access control issue in the exportXls function of the AiragModelController (located in jeecg-boot-module-airag). The vulnerability allows manipulation of the credential argument, enabling an attacker to bypass authentication or authorization checks. The flaw is remotely exploitable without requiring authentication, and the exploit has been publicly disclosed. The issue is resolved by upgrading to version 3.9.5 and applying commit a2be896f753936956ee6863b632b8e5a0231345c.

Affected products

  • JeecgBoot JeecgBoot up to 3.9.3

Timeline

  • 2026-09-06: disclosed
  • 2026-08-27: patched: Version 3.9.5 released; patch commit a2be896f753936956ee6863b632b8e5a0231345c

References

Related threats