Missing Authorization Vulnerability in JeecgBoot by Jeecg
CVE-2026-108881
Key Information:
Badges
What is CVE-2026-108881?
The JeecgBoot application version 3.9.5 has a missing authorization vulnerability within the getTenantPackInfo handler. This flaw permits any authenticated user to access and read product pack membership information for other tenants. By manipulating parameters such as tenantId and predefined packCode values like superAdmin or appAdmin, low-privileged individuals can easily disclose sensitive data, including administrator usernames, real names, phone numbers, and departmental details. This vulnerability highlights a significant security oversight that could lead to unauthorized access to critical tenant information.
Affected Version(s)
JeecgBoot 0 <= 3.9.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
