Missing Authorization Vulnerability in JeecgBoot by Jeecg
CVE-2026-108659
Key Information:
Badges
What is CVE-2026-108659?
JeecgBoot through version 3.9.5 has a missing authorization issue within the SysTenantController component. This vulnerability allows authenticated users, including those with low privileges, to exploit the listPackByTenantUserId endpoint. By manipulating the tenantId and userId parameters, attackers can enumerate product pack configurations for any tenant, potentially exposing sensitive information about tenant administrators and their associated product packs. This vulnerability underscores the importance of implementing proper access controls to safeguard against unauthorized data exposure.
Affected Version(s)
JeecgBoot 0 <= 3.9.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
