{"id":"CVE-2026-5616","summary":"JeecgBoot AI Chat JeecgBizToolsProvider.java missing authentication","details":"A security vulnerability has been detected in JeecgBoot 3.9.0/3.9.1. The impacted element is an unknown function of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/airag/JeecgBizToolsProvider.java of the component AI Chat Module. Such manipulation leads to missing authentication. The attack can be executed remotely. The name of the patch is b7c9aeba7aefda9e008ea8fe4fc3daf08d0c5b39/2c1cc88b8d983868df8c520a343d6ff4369d9e59. It is best practice to apply a patch to resolve this issue. The project fixed the issue with a commit which shall be part of the next official release.","modified":"2026-08-12T16:41:26.106533Z","published":"2026-04-06T03:15:14.731Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-287","CWE-306"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/5xxx/CVE-2026-5616.json"},"references":[{"type":"WEB","url":"https://github.com/jeecgboot/JeecgBoot/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/5xxx/CVE-2026-5616.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-5616"},{"type":"ADVISORY","url":"https://vuldb.com/submit/785570"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/355407"},{"type":"REPORT","url":"https://github.com/jeecgboot/JeecgBoot/issues/9464"},{"type":"REPORT","url":"https://vuldb.com/vuln/355407/cti"},{"type":"FIX","url":"https://github.com/jeecgboot/JeecgBoot/commit/b7c9aeba7aefda9e008ea8fe4fc3daf08d0c5b39"},{"type":"FIX","url":"https://github.com/jeecgboot/JeecgBoot/pull/9463"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/jeecgboot/jeecgboot","events":[{"introduced":"41877a6e8ba6e485bdd25e6dc5d6279e58754707"},{"fixed":"b7c9aeba7aefda9e008ea8fe4fc3daf08d0c5b39"}],"database_specific":{"extracted_events":[{"introduced":"3.9.0"},{"last_affected":"3.9.0"},{"introduced":"3.9.1"},{"last_affected":"3.9.1"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["3.9.0","3.9.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-5616.json","vanir_signatures_modified":"2026-08-12T16:41:26Z","vanir_signatures":[{"target":{"file":"jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/app/service/impl/AiragChatServiceImpl.java"},"deprecated":false,"digest":{"line_hashes":["4032648983383127606919241885467703323","308872428654025504858546986993903472027","235257306595553524674416907081595647740","235744258064397685994025451524052639290","118304717974156907368607336368096984234"],"threshold":0.9},"id":"CVE-2026-5616-48456eb3","signature_type":"Line","signature_version":"v1","source":"https://github.com/jeecgboot/jeecgboot/commit/b7c9aeba7aefda9e008ea8fe4fc3daf08d0c5b39"},{"signature_version":"v1","source":"https://github.com/jeecgboot/jeecgboot/commit/b7c9aeba7aefda9e008ea8fe4fc3daf08d0c5b39","target":{"file":"jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/app/service/impl/AiragChatServiceImpl.java","function":"sendWithDefault"},"deprecated":false,"digest":{"length":6448,"function_hash":"16985411090630716865699933953672741983"},"id":"CVE-2026-5616-ef178674","signature_type":"Function"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"}]}