PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108606 jeecgboot CVE debrief

CVE-2026-108606 is a missing authorization vulnerability in JeecgBoot through version 3.9.5, specifically in the AiOcrController deleteById handler. This allows any authenticated user to delete OCR records. Low-privileged attackers can obtain record IDs from the unguarded GET /airag/ocr/list endpoint and repeatedly delete every shared OCR prompt record stored in Redis.

Vendor
jeecgboot
Product
Unknown
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders responsible for JeecgBoot installations, particularly those with low-privileged user accounts, should assess exposure and prioritize patching or mitigating this vulnerability to prevent unauthorized deletion of OCR records.

Why it matters

CVE-2026-108606 is a medium-severity vulnerability in JeecgBoot that allows authenticated users to delete OCR records without authorization. Defenders should prioritize patching and monitoring to prevent disruption and data loss.

  • Authenticated users can delete OCR records without proper authorization, potentially disrupting shared OCR prompt records.
  • Low-privileged attackers can enumerate and delete records using the unguarded GET /airag/ocr/list endpoint.
  • Defenders need to verify and patch affected installations to prevent exploitation.
  • Monitoring for unauthorized deletions is necessary to detect potential attacks.

Technical summary

The CVE-2026-108606 vulnerability is caused by a missing authorization check in the AiOcrController deleteById handler of JeecgBoot versions up to 3.9.5. This handler allows any authenticated user to delete OCR records. An attacker can enumerate record IDs using the unguarded GET /airag/ocr/list endpoint and then delete shared OCR prompt records stored in Redis. Affected product deployments should be verified, and defenders should restrict access to the AiOcrController deleteById handler and monitor for unauthorized deletion of OCR records to prevent disruption and data loss.

Defensive priority

Defenders should prioritize verifying and patching affected JeecgBoot installations, restricting access to the AiOcrController deleteById handler, and monitoring for unauthorized deletion of OCR records.

Recommended defensive actions

  • Verify and patch affected JeecgBoot installations to restrict access to the AiOcrController deleteById handler.
  • Monitor for unauthorized deletion of OCR records.
  • Restrict access to the GET /airag/ocr/list endpoint to prevent record ID enumeration.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and source references indicate a missing authorization vulnerability in JeecgBoot's AiOcrController deleteById handler. The vulnerability allows authenticated users to delete OCR records without proper authorization. Record IDs can be obtained from the unguarded GET /airag/ocr/list endpoint.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108606 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108606

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108606 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108606

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/JeecgBoot/poc_airag_ocr_record_delete.py

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://github.com/jeecgboot/JeecgBoot/blob/e3b9dc0aefe1943d9772b026f64ed671a7c82802/jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/ocr/controller/AiOcrController.java

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/jeecgboot-through-3.9.5-missing-authorization-via-airag-ocr-deletebyid

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.