CVE-2026-86228 affects JeecgBoot, a widely used Chinese-origin open-source low-code development platform built on Spring Boot, popular for rapidly building enterprise back-office applications.
What the vulnerability does
Per the vulnerability record, the flaw is in the exportXls function of AiragModelController.java — part of JeecgBoot’s AI-agent (AIRag) module, which handles export functionality for AI-model configuration. Manipulating the credential argument leads to improper access control, and the attack can be launched remotely. Affected versions run through 3.9.3.
Improper access control on an export endpoint that handles a credential parameter is a meaningful risk: depending on exactly what the export function returns, this class of bug can allow retrieval of data or configuration that should require stricter authorization than the endpoint enforces.
Fix
Fixed in JeecgBoot 3.9.5, per the project’s own patch (commit a2be896f753936956ee6863b632b8e5a0231345c). Deployments should upgrade to 3.9.5 or later.
Confidence
This traces to JeecgBoot’s own GitHub repository, with a named function, file, and patch commit — confidence is high.
Why this matters
Low-code platforms like JeecgBoot are frequently used to stand up internal enterprise tools quickly, often by teams without a dedicated security review process for each generated application — which makes platform-level access-control bugs in JeecgBoot itself higher-leverage than they might be in a single bespoke application, since the same flaw potentially affects every application built on an unpatched platform version. Organizations running JeecgBoot-based internal tools should prioritize the 3.9.5 upgrade, particularly if the AIRag module is in active use.
Frequently Asked Questions
What is CVE-2026-86228?
An improper access control vulnerability in JeecgBoot’s AI-agent module (versions through 3.9.3), exploitable via the credential argument of the exportXls function.
Which version fixes CVE-2026-86228? JeecgBoot 3.9.5 and later.
Is CVE-2026-86228 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog.
Data sourced from the JeecgBoot project’s own GitHub repository, aggregated September 2026. See more vulnerability intelligence.