CVE-2026-108883
Received Received - Intake

JeecgBoot Missing Authorization in Third-Party App Config

Vulnerability report for CVE-2026-108883, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the editThirdAppConfig handler that allows any authenticated user to modify third-party application configurations. Low-privileged attackers can replace client id, client secret, agent id and corp id of DingTalk, WeCom or Feishu integrations to redirect directory synchronisation and messaging to attacker-controlled applications or break them.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jeecgboot JeecgBoot 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JeecgBoot through version 3.9.5 has a missing authorization vulnerability in the /sys/thirdApp/editThirdAppConfig endpoint. This flaw allows any authenticated user, even with low privileges, to modify third-party application configurations like DingTalk, WeCom, or Feishu integrations. Attackers can change critical settings such as client ID, client secret, agent ID, and corp ID, which could redirect directory synchronization and messaging to attacker-controlled applications or disrupt these services entirely.

Detection Guidance

Check for unauthorized modifications to third-party application configurations by monitoring API requests to the /sys/thirdApp/editThirdAppConfig endpoint. Look for POST requests with parameters like clientId, agentId, or clientSecret being altered without proper authorization. Use network traffic analysis tools to inspect these endpoints for suspicious activity.

Impact Analysis

Low-privileged attackers can replace credentials of third-party integrations to redirect directory synchronization and messaging to attacker-controlled applications. This could lead to data breaches, service disruption, or unauthorized access to sensitive information managed by these integrations.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Non-compliance may result in legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Immediately update JeecgBoot to a patched version beyond 3.9.5. Implement strict access controls on the /sys/thirdApp/editThirdAppConfig endpoint to ensure only authorized users can modify configurations. Review and audit all third-party application integrations for unauthorized changes to client IDs, secrets, or agent IDs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108883. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart