CVE WATCH / VULNERABILITY DETAIL

CVE-2026-108605

MEDIUMCVSS 4.3NVD feed

Published 10 October 2026 · tracked since 11 October 2026

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiOcrController updateById handler that allows any authenticated user to modify global OCR templates. Low-privileged attackers can send PUT requests to /airag/ocr/edit to overwrite LLM prompts in the shared airag:ocr Redis

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools