AuraTracer智迹闻
中文

EVENT DOSSIER

JimuReport unauthorized remote code execution vulnerability security alert

2026-09-05 08:00 Cybersecurity 🔥 42.2 heat score
1sources
1days unfolding
42.2heat score
3mentions
SummaryAI generated

On September 5, 2026, Qisanx CERT issued a security notice stating that the JimuReport (Building Report) v2.5.1 version it developed contained an unauthorized remote code execution vulnerability. This vulnerability stemmed from dual flaws in the automatic export function regarding identity verification and expression execution: attackers could forge fixed key signatures to bypass authentication and trigger the Aviator expression engine through the export interface, resulting in sandbox escape and arbitrary command execution. The PoC has been made public, with a CVSS 3.1 score of 9.8 (high risk). The impact is estimated to be on the tens of thousands of systems, and there is no need for authentication or special network conditions to exploit this vulnerability. It is recommended that customers immediately upgrade Aviator to ≥5.4.4, rotate hard-coded keys, block related interface access, and disable unauthorized parameter execution. Meanwhile, wait for the official fix version to be released.

Related eventsRELATED EVENTS
Key entitiesKEY ENTITIES
JimuReportQianxinjeecgboot

Coverage · reports per dayLANGUAGE SPLIT

Entity relations
JimuReport × Qianxin1JimuReport × jeecgboot1Qianxin × jeecgboot1

SignalsSIGNALS

Keyword heat
  • JimuReport1
  • Qianxin1
  • jeecgboot1

All reports (1)SOURCES

安全内参 zh 2026-09-05 08:00

JimuReport unauthorized remote code execution vulnerability security alert

Qianxin CERT has issued a security alert regarding the unauthorized remote code execution vulnerability in JimuReport (QVD-2026-61751). This vulnerability stems from two flaws in the automatic export function of version 2.5.1: attackers can forge fixed key signatures to bypass authentication and trigger the Aviator expression engine through the export interface, enabling sandbox escape and arbitrary command execution. The PoC has been made public, with a CVSS 3.1 score of 9.8 (high risk). The impact involves tens of thousands of systems, and there is no need for authentication or special network conditions to exploit this vulnerability. It is recommended that customers immediately upgrade Aviator to ≥5.4.4, rotate hard-coded keys, block access to related interfaces, and disable unauthorized parameter execution. Meanwhile, wait for the official fix to be released.