CVE-2026-7603: JeecgBoot LoadFile Endpoint FileDownloadUtils.jav checkPathTraversalBatch server-side request forgery
A vulnerability was determined in JeecgBoot up to 3.9.1. Affected by this issue is the function checkPathTraversalBatch of the file FileDownloadUtils.jav of the component LoadFile Endpoint. This manipulation of the argument files causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The affected component should be upgraded. The vendor confirmed the issue and will provide a fix in the upcoming release.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7603?
CVE-2026-7603 is rated as a high severity vulnerability due to its potential for server-side request forgery.
How do I fix CVE-2026-7603?
To fix CVE-2026-7603, upgrade JeecgBoot to version 3.9.2 or later where the vulnerability has been patched.
What components are affected by CVE-2026-7603?
CVE-2026-7603 affects the LoadFile Endpoint specifically in the checkPathTraversalBatch function of FileDownloadUtils.jav.
What type of vulnerability is CVE-2026-7603?
CVE-2026-7603 is characterized as a server-side request forgery vulnerability.
Which software versions are impacted by CVE-2026-7603?
JeecgBoot versions up to and including 3.9.1 are impacted by CVE-2026-7603.