CVE-2026-3026Disclosure(jeewms / jeewms)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in erzhongxmu JEEWMS 3.7. Affected by this issue is some unknown functionality of the file /plug-in/ueditor/jsp/getRemoteImage.jsp of the component UEditor. The manipulation of the argument upfile leads to server-side request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jeewms

Threat summary

  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-02-23); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
jeewms

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-23: 1Mentions · 2026-02-24: 1Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Technical Details · 2026-02-23: 1Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 102-2302-2402-2702-28
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-231
Disclosure1
2026-02-241
General1
2026-02-271
Disclosure1
2026-02-281
General1
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3026 Server-Side Request Forgery in erzhongxmu JEEWMS 3.7 via UEditor C... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3026 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    A new SSRF vulnerability (CVE-2026-3026) affecting erzhongxmu JEEWMS 3.7 via UEditor is disclosed, with a link to details but no PoC, exploit, or patch information.

    0001053
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-3026 (CVSS:6.9, HIGH) is Analyzed. A vulnerability has been found in erzhongxmu JEEWMS 3.7. Affected by this issue is some unknown functionality of the fil..https://nvd.nist.gov/vuln/detail/CVE-2026-3026 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet merely announces CVE-2026-3026 with its CVSS score and links to the NVD entry, without mentioning any PoC, exploit, or patch details.

    0000020
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3026 (CVSS:6.9, HIGH) is Analyzed. A vulnerability has been found in erzhongxmu JEEWMS 3.7. Affected by this issue is some unknown functionality of the fil..https://nvd.nist.gov/vuln/detail/CVE-2026-3026 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    A new vulnerability, CVE-2026-3026, has been identified in erzhongxmu JEEWMS 3.7 with a CVSS score of 6.9 (HIGH), though no exploitation details or patches are disclosed.

    0000020
    173 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-3026 A vulnerability has been found in erzhongxmu JEEWMS 3.7. Affected by this issue is some unknown functionality of the file /plug-in/ueditor/jsp/getRemoteImage.jsp of the… https://www.cve.org/CVERecord?id=CVE-2026-3026

    Post summary

    The text briefly references CVE-2026-3026 in erzhongxmu JEEWMS 3.7, noting an unknown issue in a specific file, but provides no further details.

    00000111
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjeewmsjeewms---

Explore more