weakness has been identified in JeecgBoot 3.9.1. This vulnerability affects the function importDocumentFromZip of the file org/jeecg/modules/airag/llm/controller/AiragKnowledgeController.java of the component Retrieval-Augmented Generation. Executing a manipulation can lead to deserialization. The attack can be launched remotely. Attacks of this nature are highly complex. It is stated that the exploitability is difficult. The project was informed of the problem early through an issue report but has not responded yet.
| Link | Resource |
|---|---|
| https://github.com/jeecgboot/JeecgBoot/ | Product |
| https://github.com/jeecgboot/JeecgBoot/issues/9335 | Exploit Issue Tracking Third Party Advisory |
| https://vuldb.com/?ctiid.346163 | Permissions Required VDB Entry |
| https://vuldb.com/?id.346163 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.750232 | Third Party Advisory VDB Entry |
| https://github.com/jeecgboot/JeecgBoot/issues/9335 | Exploit Issue Tracking Third Party Advisory |
18 Feb 2026, 21:43
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Jeecg
Jeecg jeecg Boot |
|
| CPE | cpe:2.3:a:jeecg:jeecg_boot:3.9.1:*:*:*:*:*:*:* | |
| References | () https://github.com/jeecgboot/JeecgBoot/ - Product | |
| References | () https://github.com/jeecgboot/JeecgBoot/issues/9335 - Exploit, Issue Tracking, Third Party Advisory | |
| References | () https://vuldb.com/?ctiid.346163 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.346163 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.750232 - Third Party Advisory, VDB Entry |
18 Feb 2026, 17:52
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
17 Feb 2026, 16:20
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/jeecgboot/JeecgBoot/issues/9335 - |
16 Feb 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2026-02-16 12:16
Updated : 2026-02-18 21:43
NVD link : CVE-2026-2555
Mitre link : CVE-2026-2555
CVE.ORG link : CVE-2026-2555
JSON object : View