Missing Authorization Vulnerability in JeecgBoot by Jeecg
CVE-2026-108656

5.3MEDIUM

Key Information:

Vendor

Jeecgboot

Status
Vendor
CVE Published:
10 October 2026

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2026-108656?

JeecgBoot version 3.9.5 features a vulnerability in the SysTenantController endpoint, specifically the GET /sys/tenant/getTenantPackApplyUsers functionality. This flaw allows authenticated users to bypass authorization checks and access sensitive information about tenant administrator applications. Attackers with low privileges can manipulate the tenantId parameter, enabling them to retrieve usernames, real names, phone numbers, and departmental details of pending applicants for any tenant, posing a significant risk to tenant privacy and security.

Affected Version(s)

JeecgBoot 0 <= 3.9.5

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yaqi Chao
.