Missing Authorization Vulnerability in JeecgBoot by Jeecg Technology
CVE-2026-108661
Key Information:
Badges
What is CVE-2026-108661?
JeecgBoot versions up to 3.9.5 have a vulnerability that permits authenticated users to transfer tenant ownership without adequate authorization. The API endpoint /sys/tenant/changeOwenUserTenant can be exploited by low-privileged attackers who manipulate the userId and tenantId parameters. This flaw enables unauthorized individuals to claim ownership of any tenant, potentially allowing them to remove legitimate owners and gain inappropriate access.
Affected Version(s)
JeecgBoot 0 <= 3.9.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
