Executive brief
JeecgBoot, an AI-powered low-code development platform, contains a security vulnerability in its AiragModelController component. This flaw allows an authenticated remote attacker to bypass intended access controls and potentially view sensitive data they should not be able to access. This could lead to unauthorized information disclosure within the platform. Organizations using JeecgBoot should upgrade to version 3.9.2 to mitigate this risk.
Technical details
A vulnerability exists in JeecgBoot versions up to 3.9.1 within the AiragModelController component. The root cause is improper access control (CWE-284/CWE-266) during the manipulation of the argument list in the queryById function. A remote attacker with low-level privileges can exploit this flaw to bypass authorization checks and access data outside of their permitted scope. The vulnerability has been addressed in version 3.9.2, which includes specific security hardening for Airag-related controllers and tenant isolation. Public exploit information is available.
Affected products
- JeecgBoot JeecgBoot up to 3.9.1
Timeline
- 2026-04-30: patched: Version 3.9.2 released with security fixes.
- 2026-05-26: disclosed: Vulnerability details published.