CVE-2026-1746

Source
https://cve.org/CVERecord?id=CVE-2026-1746
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-1746.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-1746
Published
2026-02-02T05:32:10.887Z
Modified
2026-07-15T01:49:05.908443521Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
JeecgBoot Online Report API loadDictItemByKeyword sql injection
Details

A vulnerability was identified in JeecgBoot 3.9.0. This vulnerability affects unknown code of the file /JeecgBoot/sys/api/loadDictItemByKeyword of the component Online Report API. Such manipulation of the argument keyword leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Database specific
{
    "cna_assigner": "VulDB",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/1xxx/CVE-2026-1746.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "3.9.0"
                },
                {
                    "last_affected": "3.9.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cwe_ids": [
        "CWE-74",
        "CWE-89"
    ]
}
References

Affected packages

Git / github.com/jeecgboot/jeecgboot

Affected ranges

Type
GIT
Repo
https://github.com/jeecgboot/jeecgboot
Events
Database specific
{
    "cpe": "cpe:2.3:a:jeecg:jeecg_boot:3.9.0:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "3.9.0"
        },
        {
            "last_affected": "3.9.0"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

3.*
3.9.0
v3.*
v3.9.0last

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-1746.json"