Unknown · Jeecg-Boot · CVE-2026-86228
**Name of the Vulnerable Software and Affected Versions**
JeecgBoot versions prior to 3.9.5
**Description**
Improper access controls exist in the `exportXls()` function within the `AiragModelController.java` file. A remote attacker can exploit this by manipulating the `credential` argument to gain unauthorized access.
**Recommendations**
Upgrade to version 3.9.5.
As a temporary workaround, restrict access to the `exportXls()` function until the update is applied.