Skip to main content
QUIETLYTIC
Vulnerability

JeecgBoot Access Control Flaw (CVE-2026-86228)

CVE-2026-86228 is an improper access control vulnerability in JeecgBoot low-code platform, exploitable via the credential argument of an AI-model export function, fixed in version 3.9.5.

CVE-2026-86228
Threat Level
MEDIUM
CVSS
4.3
Status
Monitored
Confidence
High
Affected Products
JeecgBoot

CVE-2026-86228 affects JeecgBoot, a widely used Chinese-origin open-source low-code development platform built on Spring Boot, popular for rapidly building enterprise back-office applications.

What the vulnerability does

Per the vulnerability record, the flaw is in the exportXls function of AiragModelController.java — part of JeecgBoot’s AI-agent (AIRag) module, which handles export functionality for AI-model configuration. Manipulating the credential argument leads to improper access control, and the attack can be launched remotely. Affected versions run through 3.9.3.

Improper access control on an export endpoint that handles a credential parameter is a meaningful risk: depending on exactly what the export function returns, this class of bug can allow retrieval of data or configuration that should require stricter authorization than the endpoint enforces.

Fix

Fixed in JeecgBoot 3.9.5, per the project’s own patch (commit a2be896f753936956ee6863b632b8e5a0231345c). Deployments should upgrade to 3.9.5 or later.

Confidence

This traces to JeecgBoot’s own GitHub repository, with a named function, file, and patch commit — confidence is high.

Why this matters

Low-code platforms like JeecgBoot are frequently used to stand up internal enterprise tools quickly, often by teams without a dedicated security review process for each generated application — which makes platform-level access-control bugs in JeecgBoot itself higher-leverage than they might be in a single bespoke application, since the same flaw potentially affects every application built on an unpatched platform version. Organizations running JeecgBoot-based internal tools should prioritize the 3.9.5 upgrade, particularly if the AIRag module is in active use.

Frequently Asked Questions

What is CVE-2026-86228? An improper access control vulnerability in JeecgBoot’s AI-agent module (versions through 3.9.3), exploitable via the credential argument of the exportXls function.

Which version fixes CVE-2026-86228? JeecgBoot 3.9.5 and later.

Is CVE-2026-86228 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog.


Data sourced from the JeecgBoot project’s own GitHub repository, aggregated September 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 JeecgBoot (GitHub)

Related intelligence


Analyst tools