CVE-2026-5616

Source
https://cve.org/CVERecord?id=CVE-2026-5616
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-5616.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-5616
Published
2026-04-06T03:15:14.731Z
Modified
2026-07-27T08:14:20.066042Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X CVSS Calculator
Summary
JeecgBoot AI Chat JeecgBizToolsProvider.java missing authentication
Details

A security vulnerability has been detected in JeecgBoot 3.9.0/3.9.1. The impacted element is an unknown function of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/airag/JeecgBizToolsProvider.java of the component AI Chat Module. Such manipulation leads to missing authentication. The attack can be executed remotely. The name of the patch is b7c9aeba7aefda9e008ea8fe4fc3daf08d0c5b39/2c1cc88b8d983868df8c520a343d6ff4369d9e59. It is best practice to apply a patch to resolve this issue. The project fixed the issue with a commit which shall be part of the next official release.

Database specific
{
    "cwe_ids": [
        "CWE-287",
        "CWE-306"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/5xxx/CVE-2026-5616.json",
    "cna_assigner": "VulDB"
}
References

Affected packages

Git / github.com/jeecgboot/jeecgboot

Affected ranges

Type
GIT
Repo
https://github.com/jeecgboot/jeecgboot
Events
Database specific
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "3.9.0"
        },
        {
            "last_affected": "3.9.0"
        },
        {
            "introduced": "3.9.1"
        },
        {
            "last_affected": "3.9.1"
        }
    ]
}

Affected versions

3.*
3.9.0
3.9.1

Database specific

vanir_signatures_modified
"2026-07-27T08:14:20Z"
vanir_signatures
[
    {
        "signature_type": "Line",
        "target": {
            "file": "jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/app/service/impl/AiragChatServiceImpl.java"
        },
        "deprecated": false,
        "source": "https://github.com/jeecgboot/jeecgboot/commit/b7c9aeba7aefda9e008ea8fe4fc3daf08d0c5b39",
        "id": "CVE-2026-5616-48456eb3",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "4032648983383127606919241885467703323",
                "308872428654025504858546986993903472027",
                "235257306595553524674416907081595647740",
                "235744258064397685994025451524052639290",
                "118304717974156907368607336368096984234"
            ],
            "threshold": 0.9
        }
    },
    {
        "signature_type": "Function",
        "target": {
            "file": "jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/app/service/impl/AiragChatServiceImpl.java",
            "function": "sendWithDefault"
        },
        "deprecated": false,
        "source": "https://github.com/jeecgboot/jeecgboot/commit/b7c9aeba7aefda9e008ea8fe4fc3daf08d0c5b39",
        "id": "CVE-2026-5616-ef178674",
        "signature_version": "v1",
        "digest": {
            "function_hash": "16985411090630716865699933953672741983",
            "length": 6448.0
        }
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-5616.json"