PatchSiren cyber security CVE debrief
CVE-2026-108606 jeecgboot CVE debrief
CVE-2026-108606 is a missing authorization vulnerability in JeecgBoot through version 3.9.5, specifically in the AiOcrController deleteById handler. This allows any authenticated user to delete OCR records. Low-privileged attackers can obtain record IDs from the unguarded GET /airag/ocr/list endpoint and repeatedly delete every shared OCR prompt record stored in Redis.
- Vendor
- jeecgboot
- Product
- Unknown
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for JeecgBoot installations, particularly those with low-privileged user accounts, should assess exposure and prioritize patching or mitigating this vulnerability to prevent unauthorized deletion of OCR records.
Why it matters
CVE-2026-108606 is a medium-severity vulnerability in JeecgBoot that allows authenticated users to delete OCR records without authorization. Defenders should prioritize patching and monitoring to prevent disruption and data loss.
- Authenticated users can delete OCR records without proper authorization, potentially disrupting shared OCR prompt records.
- Low-privileged attackers can enumerate and delete records using the unguarded GET /airag/ocr/list endpoint.
- Defenders need to verify and patch affected installations to prevent exploitation.
- Monitoring for unauthorized deletions is necessary to detect potential attacks.
Technical summary
The CVE-2026-108606 vulnerability is caused by a missing authorization check in the AiOcrController deleteById handler of JeecgBoot versions up to 3.9.5. This handler allows any authenticated user to delete OCR records. An attacker can enumerate record IDs using the unguarded GET /airag/ocr/list endpoint and then delete shared OCR prompt records stored in Redis. Affected product deployments should be verified, and defenders should restrict access to the AiOcrController deleteById handler and monitor for unauthorized deletion of OCR records to prevent disruption and data loss.
Defensive priority
Defenders should prioritize verifying and patching affected JeecgBoot installations, restricting access to the AiOcrController deleteById handler, and monitoring for unauthorized deletion of OCR records.
Recommended defensive actions
- Verify and patch affected JeecgBoot installations to restrict access to the AiOcrController deleteById handler.
- Monitor for unauthorized deletion of OCR records.
- Restrict access to the GET /airag/ocr/list endpoint to prevent record ID enumeration.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and source references indicate a missing authorization vulnerability in JeecgBoot's AiOcrController deleteById handler. The vulnerability allows authenticated users to delete OCR records without proper authorization. Record IDs can be obtained from the unguarded GET /airag/ocr/list endpoint.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108606 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108606
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108606 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108606
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/JeecgBoot/poc_airag_ocr_record_delete.py
-
Source reference
Unverified legacy reference
URL: https://github.com/jeecgboot/JeecgBoot/blob/e3b9dc0aefe1943d9772b026f64ed671a7c82802/jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/ocr/controller/AiOcrController.java
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/jeecgboot-through-3.9.5-missing-authorization-via-airag-ocr-deletebyid
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.