A security vulnerability has been detected in JeecgBoot 3.9.0/3.9.1. The impacted element is an unknown function of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/airag/JeecgBizToolsProvider.java of the component AI Chat Module. Such manipulation leads to missing authentication. The attack can be executed remotely. The name of the patch is b7c9aeba7aefda9e008ea8fe4fc3daf08d0c5b39/2c1cc88b8d983868df8c520a343d6ff4369d9e59. It is best practice to apply a patch to resolve this issue. The project fixed the issue with a commit which shall be part of the next official release.
{
"cwe_ids": [
"CWE-287",
"CWE-306"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/5xxx/CVE-2026-5616.json",
"cna_assigner": "VulDB"
}"2026-07-27T08:14:20Z"
[
{
"signature_type": "Line",
"target": {
"file": "jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/app/service/impl/AiragChatServiceImpl.java"
},
"deprecated": false,
"source": "https://github.com/jeecgboot/jeecgboot/commit/b7c9aeba7aefda9e008ea8fe4fc3daf08d0c5b39",
"id": "CVE-2026-5616-48456eb3",
"signature_version": "v1",
"digest": {
"line_hashes": [
"4032648983383127606919241885467703323",
"308872428654025504858546986993903472027",
"235257306595553524674416907081595647740",
"235744258064397685994025451524052639290",
"118304717974156907368607336368096984234"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"target": {
"file": "jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/app/service/impl/AiragChatServiceImpl.java",
"function": "sendWithDefault"
},
"deprecated": false,
"source": "https://github.com/jeecgboot/jeecgboot/commit/b7c9aeba7aefda9e008ea8fe4fc3daf08d0c5b39",
"id": "CVE-2026-5616-ef178674",
"signature_version": "v1",
"digest": {
"function_hash": "16985411090630716865699933953672741983",
"length": 6448.0
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-5616.json"