CVE-2026-108672
JeecgBoot through 3.9.5 contains an authorization bypass vulnerability in the getVideoRecords handler of VideoGenerationController that allows authenticated users to read other users' records via the userId parameter. Low-privileged attackers can supply another user id to retrieve their AI video generation history, including prompts, task ids, video URLs and cover URLs.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- CWE
- CWE-639
- Published
- 2026-10-10
- Last modified
- 2026-10-10
Affected products
- jeecgboot JeecgBoot
Weakness type
Related vulnerabilities
- CVE-2026-103009 — Authorization Bypass Through User-Controlled Key in Elasticsearch Leading to Information Disclosure
- CVE-2026-105859 — Payload: Unauthorized update to collection documents
- CVE-2026-105639 — Plane: Pre-auth workspace invitation hijack via email-squat and self-served invitation token leak in Plane
- CVE-2026-105637 — Plane: Cross-Project Asset Hijacking via 'ProjectBulkAssetEndpoint' (sibling of CVE-2026-46558)
- CVE-2026-91107 — openSIS Classic 9.3 - Insecure Direct Object Reference (IDOR)
- CVE-2026-74864 — Authentication Bypass in sogo_yhn
- CVE-2026-101084 — obot before v0.21.1 Authorization Bypass via /mcp-connect
- CVE-2026-74865 — Authentication Bypass in sogo_yhn