SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86228

MEDIUM · CVSS 4.3 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-06 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

JeecgBoot versions up to 3.9.3 contain a vulnerability in the exportXls function that allows for improper access controls due to argument manipulation, potentially enabling remote attacks. Organizations using affected versions of JeecgBoot should prioritize upgrading to version 3.9.5 to mitigate this risk, as the exploit has been publicly disclosed. Immediate action is recommended to protect sensitive data and maintain system integrity.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86228
Severity
MEDIUM
CVSS
4.3
EPSS
0.23%
Java

Original NVD Description

A security vulnerability has been detected in JeecgBoot up to 3.9.3. This vulnerability affects the function exportXls of the file jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/llm/controller/AiragModelController.java. Such manipulation of the argument credential leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 3.9.5 is able to resolve this issue. The name of the patch is a2be896f753936956ee6863b632b8e5a0231345c. You should upgrade the affected component.