Ghostwire

CVE-2026-108607: JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability that allows authenticated users to...

MEDIUM CVSS 4.3 Exploit Available

Published: October 10, 2026 | Last Modified: October 10, 2026

Description

JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability that allows authenticated users to delete other users' AI video generation records by supplying arbitrary userId values to DELETE /airag/video/deleteVideoRecord. Attackers can obtain record ids from the unchecked GET /airag/video/listByUser endpoint and delete victims' Redis-stored video history entries one record per request.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References