CVE-2026-11502: JeecgBoot Third-Party Login ThirdLoginController.java HttpServletResponse.sendRedirect redirect

Published Jun 8, 2026
·
Updated

A weakness has been identified in JeecgBoot up to 3.9.2. Impacted is the function HttpServletResponse.sendRedirect of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/ThirdLoginController.java of the component Third-Party Login. This manipulation of the argument state causes open redirect. The attack can be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is considered difficult. The exploit has been made available to the public and could be used for attacks. The project replied: "After evaluation, this vulnerability has low exploitability in real-world scenarios: 1) Exploiting this vulnerability requires attackers to use social engineering techniques to induce victims to actively click on an OAuth login link constructed by the attacker; it cannot be triggered passively. 2) Third-party login (DingTalk/WeChat, etc.) is an optional feature and may not be enabled in most projects."

Affected Software

1 affected component
Jeecg JeecgBoot<=3.9.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove jeecg-module-system/jeecg-system-biz (Third-Party Login / ThirdLoginController) from your environment.

    Uninstall or remove the Third-Party Login module/component if it is not required to avoid the open-redirect vulnerability in ThirdLoginController.

  2. Configuration

    Disable the Third-Party Login feature (e.g., DingTalk/WeChat OAuth) if it is not required to eliminate the vulnerable redirect path in ThirdLoginController.

    JeecgBoot Third-Party Login (ThirdLoginController in jeecg-module-system/jeecg-system-biz) Third-Party Login feature = disabled
  3. Compensating control

    Educate users and administrators that exploitation requires social engineering (clicking attacker-crafted OAuth/login links); instruct users not to click OAuth/login links from untrusted sources and limit use of external OAuth login links while a code fix is pending.

Event History

Jun 8, 2026
CVE Published
via MITRE·09:30 AM
Data Sourced
via MITRE·09:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-11502?

The severity of CVE-2026-11502 is rated low with a score of 3.1.

2

How do I fix CVE-2026-11502?

To mitigate CVE-2026-11502, update JeecgBoot to the latest version that addresses this vulnerability.

3

What component is affected by CVE-2026-11502?

CVE-2026-11502 affects the Third-Party Login component in JeecgBoot up to version 3.9.2.

4

What functionality is compromised in CVE-2026-11502?

CVE-2026-11502 compromises the HttpServletResponse.sendRedirect function in the ThirdLoginController.java file.

5

Is user interaction required to exploit CVE-2026-11502?

Yes, user interaction is required for the successful exploitation of CVE-2026-11502.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203