CVE-2026-19000: JeecgBoot Anonymous Chat Attachment send server-side request forgery
A vulnerability was identified in JeecgBoot up to 3.9.2. The affected element is an unknown function of the file /airag/chat/send of the component Anonymous Chat Attachment Parser. The manipulation leads to server-side request forgery. The attack can be initiated remotely. The exploit is publicly available and might be used. A fix is planned for the upcoming release.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19000?
The severity of CVE-2026-19000 is rated as high with a score of 7.3.
How does CVE-2026-19000 impact JeecgBoot?
CVE-2026-19000 allows for server-side request forgery which can be exploited remotely.
What versions of JeecgBoot are affected by CVE-2026-19000?
CVE-2026-19000 affects JeecgBoot versions up to 3.9.2.
How do I fix CVE-2026-19000?
To fix CVE-2026-19000, upgrade to a patched version of JeecgBoot that resolves this vulnerability.
Can CVE-2026-19000 be exploited remotely?
Yes, CVE-2026-19000 can be exploited remotely, allowing attackers to manipulate server requests.