CVE WATCH / VULNERABILITY DETAIL
CVE-2026-108605
MEDIUMCVSS 4.3NVD feed
Published 10 October 2026 · tracked since 11 October 2026
Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiOcrController updateById handler that allows any authenticated user to modify global OCR templates. Low-privileged attackers can send PUT requests to /airag/ocr/edit to overwrite LLM prompts in the shared airag:ocr Redis
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-108606 MEDIUM 5.4
- CVE-2026-108607 MEDIUM 4.3
- CVE-2026-108608 MEDIUM 4.3
- CVE-2026-108609 MEDIUM 4.3
- CVE-2026-78533 CRITICAL 9.8
- CVE-2026-78535 CRITICAL 9.8
- CVE-2026-81797 CRITICAL 9.8
- CVE-2026-66567 CRITICAL 9.8
- CVE-2026-66568 CRITICAL 9.8
- CVE-2026-66569 CRITICAL 9.8