Open Redirect Vulnerability in JeecgBoot Third-Party Login Functionality
CVE-2026-11502
Key Information:
Badges
What is CVE-2026-11502?
A vulnerability exists in JeecgBoot versions up to 3.9.2 due to a flaw in the Third-Party Login functionality. This weakness allows an attacker to manipulate the state argument in the HttpServletResponse.sendRedirect method, resulting in an open redirect. Although the attack requires a degree of complexity and social engineering tactics to induce user interaction with a malicious OAuth link, the potential for exploitation remains concerning. Notably, the third-party login feature is optional and often disabled in many deployments, reducing the overall risk in practical scenarios.
Affected Version(s)
JeecgBoot 3.9.0
JeecgBoot 3.9.1
JeecgBoot 3.9.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
