CVE-2026-11502

LOW

JeecgBoot Third-Party Login ThirdLoginController.java HttpServletResponse.sendRedirect redirect

Title source: cna
STIX 2.1

Description

A weakness has been identified in JeecgBoot up to 3.9.2. Impacted is the function HttpServletResponse.sendRedirect of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/ThirdLoginController.java of the component Third-Party Login. This manipulation of the argument state causes open redirect. The attack can be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is considered difficult. The exploit has been made available to the public and could be used for attacks. The project replied: "After evaluation, this vulnerability has low exploitability in real-world scenarios: 1) Exploiting this vulnerability requires attackers to use social engineering techniques to induce victims to actively click on an OAuth login link constructed by the attacker; it cannot be triggered passively. 2) Third-party login (DingTalk/WeChat, etc.) is an optional feature and may not be enabled in most projects."

References (7)

Core 7
Core References
Third Party Advisory third-party-advisory
Submit #835622 | https://github.com/jeecgboot/JeecgBoot JeecgBoot v3.9.2 Open Redirect
https://vuldb.com/submit/835622
Vdb Entry, Technical Description vdb-entry technical-description
VDB-369122 | JeecgBoot Third-Party Login ThirdLoginController.java HttpServletResponse.sendRedirect redirect
https://vuldb.com/vuln/369122
Signature, Permissions Required signature permissions-required
VDB-369122 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/369122/cti
Third Party Advisory third-party-advisory
CVE-2026-11502 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-11502

Scores

CVSS v3 3.1
EPSS 0.0038
EPSS Percentile 29.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (3)
None/JeecgBoot 3.9.0
None/JeecgBoot 3.9.1
None/JeecgBoot 3.9.2
Published Jun 08, 2026
Tracked Since Jun 08, 2026