CVE-2026-86228 | JeecgBoot up to 3.9.3 AiragModelController.java exportXls credential access control (Issue 9600)
A vulnerability, which was classified as problematic, was found in JeecgBoot up to 3.9.3. This vulnerability affects the function exportXls of the file jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/llm/controller/AiragModelController.java. Such manipulation of the argument credential leads to improper access controls.
This vulnerability is referenced as CVE-2026-86228. It is possible to launch the attack remotely. Furthermore, an exploit is available.
You should upgrade the affected component.