CVE-2026-11502: Open Redirect in JeecgBoot
An open redirect vulnerability exists in JeecgBoot versions 3.9.0 through 3.9.2 in the Third-Party Login component. The issue arises from improper handling of the argument to HttpServletResponse.sendRedirect in the ThirdLoginController.java file. Exploitation requires user interaction via social engineering to click a malicious OAuth login link. The vulnerability has low exploitability and a low CVSS score of 2.3. The third-party login feature is optional and may not be enabled in many deployments.
AI Analysis
Technical Summary
JeecgBoot versions 3.9.0, 3.9.1, and 3.9.2 contain an open redirect vulnerability in the Third-Party Login component, specifically in the HttpServletResponse.sendRedirect call within ThirdLoginController.java. This vulnerability allows an attacker to manipulate the redirect URL parameter, potentially redirecting users to arbitrary external sites. Exploitation requires a high degree of complexity, including social engineering to convince victims to click a crafted OAuth login link. The vulnerability cannot be triggered passively and is limited by the optional nature of the third-party login feature. No official patch or remediation level has been provided by the vendor as of the publication date.
Potential Impact
Successful exploitation could redirect users to attacker-controlled websites, potentially facilitating phishing or other social engineering attacks. However, the impact is limited by the requirement for user interaction and the optional status of the affected feature. The CVSS 4.0 base score is 2.3, indicating low severity and low exploitability in real-world scenarios.
Mitigation Recommendations
No official patch or remediation has been announced. Users should evaluate whether the third-party login feature is enabled and consider disabling it if not needed. Additionally, caution should be exercised with OAuth login links, and users should be educated to avoid clicking suspicious or unsolicited links. Monitor vendor advisories for any future updates or patches addressing this issue.
CVE-2026-11502: Open Redirect in JeecgBoot
Description
An open redirect vulnerability exists in JeecgBoot versions 3.9.0 through 3.9.2 in the Third-Party Login component. The issue arises from improper handling of the argument to HttpServletResponse.sendRedirect in the ThirdLoginController.java file. Exploitation requires user interaction via social engineering to click a malicious OAuth login link. The vulnerability has low exploitability and a low CVSS score of 2.3. The third-party login feature is optional and may not be enabled in many deployments.
CVSS v4.0
Score 2.3low
Affected software
pkg:maven/org.jeecg/jeecgbootRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
JeecgBoot versions 3.9.0, 3.9.1, and 3.9.2 contain an open redirect vulnerability in the Third-Party Login component, specifically in the HttpServletResponse.sendRedirect call within ThirdLoginController.java. This vulnerability allows an attacker to manipulate the redirect URL parameter, potentially redirecting users to arbitrary external sites. Exploitation requires a high degree of complexity, including social engineering to convince victims to click a crafted OAuth login link. The vulnerability cannot be triggered passively and is limited by the optional nature of the third-party login feature. No official patch or remediation level has been provided by the vendor as of the publication date.
Potential Impact
Successful exploitation could redirect users to attacker-controlled websites, potentially facilitating phishing or other social engineering attacks. However, the impact is limited by the requirement for user interaction and the optional status of the affected feature. The CVSS 4.0 base score is 2.3, indicating low severity and low exploitability in real-world scenarios.
Mitigation Recommendations
No official patch or remediation has been announced. Users should evaluate whether the third-party login feature is enabled and consider disabling it if not needed. Additionally, caution should be exercised with OAuth login links, and users should be educated to avoid clicking suspicious or unsolicited links. Monitor vendor advisories for any future updates or patches addressing this issue.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-06-07T13:48:50.936Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a269395e29bf47b50d3c346
Added to database: 06/08/2026, 10:04:05 UTC
Last enriched: 06/16/2026, 08:35:08 UTC
Last updated: 07/31/2026, 19:22:57 UTC
Views: 74
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.