CVE WATCH / VULNERABILITY DETAIL

CVE-2026-108606

MEDIUMCVSS 5.4NVD feed

Published 10 October 2026 · tracked since 11 October 2026

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiOcrController deleteById handler that allows any authenticated user to delete OCR records. Low-privileged attackers can obtain record ids from the unguarded GET /airag/ocr/list endpoint and repeatedly delete every shared

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools