Missing Authorization Vulnerability in JeecgBoot by Jeecg
CVE-2026-108656
5.3MEDIUM
Key Information:
Badges
๐พ Exploit Exists
What is CVE-2026-108656?
JeecgBoot version 3.9.5 features a vulnerability in the SysTenantController endpoint, specifically the GET /sys/tenant/getTenantPackApplyUsers functionality. This flaw allows authenticated users to bypass authorization checks and access sensitive information about tenant administrator applications. Attackers with low privileges can manipulate the tenantId parameter, enabling them to retrieve usernames, real names, phone numbers, and departmental details of pending applicants for any tenant, posing a significant risk to tenant privacy and security.
Affected Version(s)
JeecgBoot 0 <= 3.9.5
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Yaqi Chao
