OFFLINE
Awaiting data
Security intelligence
MinorCritical vulnerability

CVE-2026-108883 (CVSS 7.1)

NVD · officialPublished Oct 11, 2026Risk 23/100

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the editThirdAppConfig handler that allows any authenticated user to modify third-party application configurations. Low-privileged attackers can replace client id, client secret, agent id and corp id of DingTalk, WeCom or Feishu integrations to redirect directory synchronisation and messaging to attacker-controlled applications or break them.

CVSS
7.1
AV:NetworkAC:LowPR:LowUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source