Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-108609

MEDIUM NVD
CVSS Score 4.3
Severity MEDIUM
Published Oct 10, 2026
Vendor unknown

Description

JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability that allows authenticated users to read other users' AI voice generation history via the userId parameter of GET /airag/voice/listByUser. Attackers who know another user's id can retrieve submitted text-to-speech input, voice settings, timestamps, and generated audio file names and paths stored in Redis.

References