PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108610 jeecgboot CVE debrief

CVE-2026-108610 is a missing authorization vulnerability in JeecgBoot through 3.9.5, specifically in the AigcWordTemplateController edit handler. This allows any authenticated user to modify word templates by sending PUT or POST requests to /airag/word/edit, potentially overwriting shared templates that other users rely on to generate documents. The vulnerability requires authentication and has a limited scope of impact, but system administrators and security teams should assess exposure and prioritize remediation to prevent exploitation.

Vendor
jeecgboot
Product
Unknown
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

System administrators and security teams responsible for JeecgBoot deployments, especially those with low-privileged user accounts, should assess exposure and prioritize remediation.

Why it matters

CVE-2026-108610 is a missing authorization vulnerability in JeecgBoot that allows authenticated users to modify word templates. Low-privileged attackers can exploit this vulnerability to overwrite shared templates, potentially disrupting document generation. System administrators and security teams should assess exposure, prioritize remediation, and verify user access controls and template management to prevent exploitation.

  • Low-privileged users can modify shared word templates, potentially disrupting document generation for other users.
  • Lack of authorization checks allows unauthorized template modifications, increasing the risk of data integrity issues.
  • Verification of user access controls and template management is necessary to prevent exploitation.
  • Remediation priority is low to medium, as the vulnerability requires authentication and has a limited scope of impact.

Technical summary

The AigcWordTemplateController edit handler in JeecgBoot through 3.9.5 does not properly enforce authorization, allowing any authenticated user to modify word templates by sending PUT or POST requests to /airag/word/edit. This could lead to overwriting of shared templates used by other users to generate documents. The vulnerability has a CVSS score of 5.3 and a medium severity, indicating a low to medium priority for authentication and authorization review, especially for users with low privileges. Defensive measures include reviewing and updating authentication and authorization settings, restricting access to the /airag/word/edit endpoint, and monitoring for potential template modifications.

Defensive priority

Low to medium priority for authentication and authorization review, especially for users with low privileges.

Recommended defensive actions

  • Review and update authentication and authorization settings for the AigcWordTemplateController edit handler.
  • Restrict access to the /airag/word/edit endpoint to authorized users only.
  • Monitor for and respond to potential template modifications by low-privileged users.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. However, the exact scope of affected versions and potential impact requires further verification from official sources. Affected product deployments should be confirmed in managed environments, and owners assigned for follow-up. Official advisories or CVE records should be reviewed to validate affected scope, severity, and vendor guidance. Vendor-supported updates or mitigations should be planned through normal change control where exposure is confirmed.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108610 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108610

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108610 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108610

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/JeecgBoot/poc_airag_word_template_edit.py

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://github.com/jeecgboot/JeecgBoot/blob/e3b9dc0aefe1943d9772b026f64ed671a7c82802/jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/wordtpl/controller/AigcWordTemplateController.java

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/jeecgboot-through-3.9.5-missing-authorization-via-airag-word-edit-endpoint

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.