{"data":{"id":"5fbb1069-ac85-454e-b3cd-a33013f85c16","title":"CVE-2026-108670: JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the promptExperiment handler of…","summary":"JeecgBoot through 3.9.5 has a missing authorization flaw in the promptExperiment handler of AiragPromptsController. Any authenticated user can run AI prompt experiments, including with other users' prompt template and dataset ids, which triggers LLM evaluation runs, writes result rows into airag_ext_data, and changes dataset status.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-108670","publishedAt":"2026-10-10T22:16:43.777Z","cveId":"CVE-2026-108670","cweIds":["CWE-862"],"cvssScore":"4.3","cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedPackageRefs":null,"affectedVendors":[],"affectedVendorsRaw":["JeecgBoot AiragPromptsController"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":"JeecgBoot missing authorization in AiragPromptsController","headlinePromptVersion":"h1","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"epssCheckedAt":"2026-10-11T00:10:11.212Z","kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"affectedPackagesCheckedAt":"2026-10-11T00:10:14.136Z","patchAvailable":null,"disclosureDate":"2026-10-10T22:16:43.777Z","capecIds":["CAPEC-122"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["integrity","confidentiality"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}