---
id: CVE-2026-86228
title: A security vulnerability has been detected in JeecgBoot up to 3.9.3
summary: >-
  A security vulnerability has been detected in JeecgBoot up to 3.9.3. This
  vulnerability affects the function exportXls of the file
  jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/llm/controller/…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-266
  - CWE-284
product: JeecgBoot
affected:
  - JeecgBoot 3.9.0
  - JeecgBoot 3.9.1
  - JeecgBoot 3.9.2
  - JeecgBoot 3.9.3
published: '2026-09-06'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T14:17:32.613'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86228'
references:
  - url: 'https://github.com/jeecgboot/JeecgBoot/'
    label: cna@vuldb.com
  - url: >-
      https://github.com/jeecgboot/JeecgBoot/commit/a2be896f753936956ee6863b632b8e5a0231345c
    label: cna@vuldb.com
  - url: 'https://github.com/jeecgboot/JeecgBoot/issues/9600'
    label: cna@vuldb.com
  - url: 'https://github.com/jeecgboot/JeecgBoot/releases/tag/v3.9.5'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-86228'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/898368'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/399381'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/399381/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T13:37:08.892457Z'
epss: 0.00394
epssPercentile: 0.30918
ingestedAt: '2026-09-07T12:10:14.503Z'
---

## Overview

A security vulnerability has been detected in JeecgBoot up to 3.9.3. This vulnerability affects the function exportXls of the file jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/llm/controller/AiragModelController.java. Such manipulation of the argument credential leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 3.9.5 is able to resolve this issue. The name of the patch is a2be896f753936956ee6863b632b8e5a0231345c. You should upgrade the affected component.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
