CVE WATCH / VULNERABILITY DETAIL
CVE-2026-108609
MEDIUMCVSS 4.3NVD feed
Published 10 October 2026 · tracked since 11 October 2026
Description
JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability that allows authenticated users to read other users' AI voice generation history via the userId parameter of GET /airag/voice/listByUser. Attackers who know another user's id can retrieve submitted text-to-speech inpu
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-108605 MEDIUM 4.3
- CVE-2026-108606 MEDIUM 5.4
- CVE-2026-108607 MEDIUM 4.3
- CVE-2026-108608 MEDIUM 4.3
- CVE-2026-78533 CRITICAL 9.8
- CVE-2026-78535 CRITICAL 9.8
- CVE-2026-81797 CRITICAL 9.8
- CVE-2026-66567 CRITICAL 9.8
- CVE-2026-66568 CRITICAL 9.8
- CVE-2026-66569 CRITICAL 9.8