CVE-2026-10239: JeecgBoot edit WordUtil.addImage server-side request forgery
Published Jun 1, 2026
·Updated
A vulnerability was determined in JeecgBoot up to 3.9.2. The affected element is the function WordUtil.addImage of the file /airag/word/edit. Executing a manipulation can lead to server-side request forgery. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. A fix is planned for the upcoming release.
Affected Software
1 affected component
JeecgBoot JeecgBoot<=3.9.2
Event History
Jun 1, 2026
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-10239?
The severity of CVE-2026-10239 is medium with a score of 6.3.
2
What type of vulnerability is CVE-2026-10239?
CVE-2026-10239 is classified as a server-side request forgery (SSRF) vulnerability.
3
How do I fix CVE-2026-10239?
To fix CVE-2026-10239, update JeecgBoot to version 3.9.3 or above.
4
Which component is affected by CVE-2026-10239?
CVE-2026-10239 affects the WordUtil.addImage function in the JeecgBoot application.
5
Can CVE-2026-10239 be exploited remotely?
Yes, CVE-2026-10239 can be exploited remotely, posing a significant risk to the affected systems.