PatchSiren cyber security CVE debrief
CVE-2026-108610 jeecgboot CVE debrief
CVE-2026-108610 is a missing authorization vulnerability in JeecgBoot through 3.9.5, specifically in the AigcWordTemplateController edit handler. This allows any authenticated user to modify word templates by sending PUT or POST requests to /airag/word/edit, potentially overwriting shared templates that other users rely on to generate documents. The vulnerability requires authentication and has a limited scope of impact, but system administrators and security teams should assess exposure and prioritize remediation to prevent exploitation.
- Vendor
- jeecgboot
- Product
- Unknown
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
System administrators and security teams responsible for JeecgBoot deployments, especially those with low-privileged user accounts, should assess exposure and prioritize remediation.
Why it matters
CVE-2026-108610 is a missing authorization vulnerability in JeecgBoot that allows authenticated users to modify word templates. Low-privileged attackers can exploit this vulnerability to overwrite shared templates, potentially disrupting document generation. System administrators and security teams should assess exposure, prioritize remediation, and verify user access controls and template management to prevent exploitation.
- Low-privileged users can modify shared word templates, potentially disrupting document generation for other users.
- Lack of authorization checks allows unauthorized template modifications, increasing the risk of data integrity issues.
- Verification of user access controls and template management is necessary to prevent exploitation.
- Remediation priority is low to medium, as the vulnerability requires authentication and has a limited scope of impact.
Technical summary
The AigcWordTemplateController edit handler in JeecgBoot through 3.9.5 does not properly enforce authorization, allowing any authenticated user to modify word templates by sending PUT or POST requests to /airag/word/edit. This could lead to overwriting of shared templates used by other users to generate documents. The vulnerability has a CVSS score of 5.3 and a medium severity, indicating a low to medium priority for authentication and authorization review, especially for users with low privileges. Defensive measures include reviewing and updating authentication and authorization settings, restricting access to the /airag/word/edit endpoint, and monitoring for potential template modifications.
Defensive priority
Low to medium priority for authentication and authorization review, especially for users with low privileges.
Recommended defensive actions
- Review and update authentication and authorization settings for the AigcWordTemplateController edit handler.
- Restrict access to the /airag/word/edit endpoint to authorized users only.
- Monitor for and respond to potential template modifications by low-privileged users.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. However, the exact scope of affected versions and potential impact requires further verification from official sources. Affected product deployments should be confirmed in managed environments, and owners assigned for follow-up. Official advisories or CVE records should be reviewed to validate affected scope, severity, and vendor guidance. Vendor-supported updates or mitigations should be planned through normal change control where exposure is confirmed.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108610 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108610
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108610 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108610
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/JeecgBoot/poc_airag_word_template_edit.py
-
Source reference
Unverified legacy reference
URL: https://github.com/jeecgboot/JeecgBoot/blob/e3b9dc0aefe1943d9772b026f64ed671a7c82802/jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/wordtpl/controller/AigcWordTemplateController.java
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/jeecgboot-through-3.9.5-missing-authorization-via-airag-word-edit-endpoint
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.