CVE-2026-108883: JeecgBoot through 3.9.5 Missing Authorization via /sys/thirdApp/editThirdAppConfig
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the editThirdAppConfig handler that allows any authenticated user to modify third-party application configurations. Low-privileged attackers can replace client id, client secret, agent id and corp id of DingTalk, WeCom or Feishu integrations to redirect directory synchronisation and messaging to attacker-controlled applications or break them.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated JeecgBoot user, including a low-privileged account, can exploit the affected handler. No user interaction is required.
Which integrations can be affected?
DingTalk, WeCom, and Feishu third-party application configurations are affected. An attacker can alter the client ID, client secret, agent ID, and corporation ID values for these integrations.
What is the practical impact of a successful change?
An attacker can redirect directory synchronization and messaging to attacker-controlled applications. They can also disrupt these integration functions by replacing configuration values with invalid ones.
How can I determine whether my deployment is affected?
Deployments running JeecgBoot through version 3.9.5 are affected if they expose and use the /sys/thirdApp/editThirdAppConfig handler. Review third-party application configuration values and related changes for unexpected client IDs, secrets, agent IDs, or corporation IDs.