Description
A vulnerability was identified in JeecgBoot up to 3.9.1. This affects the function OpenApiController.add/OpenApiController.call of the file OpenApiController.java of the component OpenApi Service. Such manipulation of the argument originUrl database leads to server-side request forgery. It is possible to launch the attack remotely. The exploit is publicly available and might be used. It is suggested to upgrade the affected component. The vendor confirmed the issue and will provide a fix in the upcoming release.
INFO
Published Date :
2026-05-02T04:45:12.477Z
Last Modified :
2026-05-02T04:45:12.477Z
Source :
VulDB
AFFECTED PRODUCTS
The following products are affected by CVE-2026-7604 vulnerability.
No data.
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-7604.