CVE-2026-8114Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in JeecgBoot up to 3.9.1. Affected by this issue is some unknown functionality of the file /sys/dict/loadTreeData of the component JSON Object Handler. The manipulation of the argument condition leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor confirms (translated from Chinese): "It should have been fixed; a batch of issues were recently resolved."

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-08); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-08: 1Mentions · 2026-05-10: 1Technical Details · 2026-05-08: 105-0805-10
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-081
Disclosure1
2026-05-101
General1
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-8114 A vulnerability was identified in JeecgBoot up to 3.9.1. Affected by this issue is some unknown functionality of the file /sys/dict/loadTreeData of the component JSON O… https://www.cve.org/CVERecord?id=CVE-2026-8114

    Post summary

    The text lists a CVE record for JeecgBoot with a brief mention of a potentially problematic file, but provides no concrete technical details, exploit information, or mitigation advice.

    00000179
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8114 SQL Injection in JeecgBoot Up to 3.9.1 JSON Object Handler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8114

    Post summary

    The text references CVE-2026-8114, describing a SQL injection vulnerability in JeecgBoot up to 3.9.1, but lacks PoC, exploit, patch, or active exploitation details.

    0000062
    4.0K followersView on X

Explore more