Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-67926: JeecgBoot AI Chat Module Code Execution Vulnerability

CVE-2026-67926 · published 17 days ago
Summary

A security issue in JeecgBoot v.3.9.2 allows an attacker to run unauthorized code on your server. This could lead to data theft, system crashes, or other malicious actions. We recommend updating to the latest version of JeecgBoot to fix this issue.

Original advisory text
An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the files Parameter in JeecgBoot AI Chat Module
An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the files Parameter in JeecgBoot AI Chat Module
Severity
9.8 Critical
Exploitation
EPSS <1%
Type
CWE-94Code Injection
Timeline
Published17 Aug 2026
Updated3 Sep 2026
First seen17 Aug 2026
Sources
CVE-2026-67926 · MITRE
Monitor software like this
Free during beta