Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 26 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 25 May 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jeecg
Jeecg jeecgboot |
|
| Vendors & Products |
Jeecg
Jeecg jeecgboot |
Sun, 24 May 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in JeecgBoot 3.9.1. This issue affects some unknown processing of the file /openapi/call/ of the component OpenAPI Endpoint. Such manipulation leads to improper authentication. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is assessed as difficult. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | JeecgBoot OpenAPI Endpoint call improper authentication | |
| First Time appeared |
Jeecgboot
Jeecgboot jeecgboot |
|
| Weaknesses | CWE-287 | |
| CPEs | cpe:2.3:a:jeecgboot:jeecgboot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Jeecgboot
Jeecgboot jeecgboot |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-05-26T13:29:46.974Z
Reserved: 2026-05-23T14:12:51.249Z
Link: CVE-2026-9373
Updated: 2026-05-26T13:29:43.164Z
Status : Deferred
Published: 2026-05-24T11:16:34.167
Modified: 2026-06-17T11:05:07.497
Link: CVE-2026-9373
No data.
OpenCVE Enrichment
Updated: 2026-05-25T11:30:23Z