A security vulnerability has been detected in JeecgBoot up to 3.9.1. The affected element is an unknown function of the file /jeecgboot/sys/dict/loadDict/airag_app,1,create_by of the component Backend Interface. Such manipulation of the argument keyword leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
References
| Link | Resource |
|---|---|
| https://vuldb.com/?ctiid.346947 | Permissions Required VDB Entry |
| https://vuldb.com/?id.346947 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.753792 | Third Party Advisory VDB Entry |
| https://www.yuque.com/meizhiyuwai/ha3yxb/lowxgbh5nne881e6 | Exploit Third Party Advisory |
Configurations
History
24 Feb 2026, 20:45
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Jeecg jeecg Boot
Jeecg |
|
| CPE | cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:* | |
| References | () https://vuldb.com/?ctiid.346947 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.346947 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.753792 - Third Party Advisory, VDB Entry | |
| References | () https://www.yuque.com/meizhiyuwai/ha3yxb/lowxgbh5nne881e6 - Exploit, Third Party Advisory |
20 Feb 2026, 13:49
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
20 Feb 2026, 05:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-20 05:17
Updated : 2026-02-24 20:45
NVD link : CVE-2026-2822
Mitre link : CVE-2026-2822
CVE.ORG link : CVE-2026-2822
JSON object : View
Products Affected
jeecg
- jeecg_boot
