CVE-2026-10240: JeecgBoot test server-side request forgery
A vulnerability was identified in JeecgBoot up to 3.9.2. The impacted element is an unknown function of the file /airag/airagModel/test. The manipulation of the argument baseUrl leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. A fix is planned for the upcoming release.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10240?
The severity of CVE-2026-10240 is rated as medium with a score of 6.3.
How do I fix CVE-2026-10240?
To fix CVE-2026-10240, update JeecgBoot to version 3.9.3 or later.
What type of vulnerability is CVE-2026-10240?
CVE-2026-10240 is classified as a server-side request forgery (SSRF) vulnerability.
What is affected by CVE-2026-10240?
CVE-2026-10240 affects the JeecgBoot up to version 3.9.2, specifically an unknown function in /airag/airagModel/test.
Can CVE-2026-10240 be exploited remotely?
Yes, CVE-2026-10240 can be exploited remotely due to its server-side request forgery nature.