CVE-2026-108658
Received Received - Intake

JeecgBoot Missing Authorization Exposes Tenant Records

Vulnerability report for CVE-2026-108658, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController queryTenantAuthInfo handler that allows any authenticated user to read other tenants' records. Low-privileged attackers can iterate small integer tenant ids to retrieve full sys_tenant records, including house numbers used as tenant join codes and company profile fields.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jeecgboot JeecgBoot 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in JeecgBoot through version 3.9.5 is a missing authorization issue in the SysTenantController queryTenantAuthInfo handler. It allows any authenticated user to read records belonging to other tenants by iterating small integer tenant IDs. Attackers can retrieve full sys_tenant records, including sensitive data like house numbers used as tenant join codes and company profile fields.

Detection Guidance

Check for unauthorized access to sys_tenant records by monitoring API calls to /sys/tenant/queryTenantAuthInfo. Look for repeated requests with small integer tenant IDs. Use tools like curl to test if low-privileged users can retrieve other tenants' data: curl -X POST http://<target>/sys/tenant/queryTenantAuthInfo -d 'tenantId=1'

Inspect application logs for suspicious queries targeting tenant records. Enable debug logging in JeecgBoot to capture detailed request information.

Impact Analysis

Low-privileged attackers could exploit this to access sensitive tenant data, including join codes and company details. This could lead to unauthorized access to tenant-specific information, potential data breaches, and misuse of confidential business or personal data.

Compliance Impact

This vulnerability could violate data protection regulations like GDPR or HIPAA by exposing sensitive tenant data to unauthorized users. Non-compliance may result in legal penalties, fines, or reputational damage due to unauthorized data access or disclosure.

Mitigation Strategies

Upgrade JeecgBoot to version 3.9.5 or later to patch the missing authorization flaw. If immediate upgrade is not possible, restrict access to the /sys/tenant/queryTenantAuthInfo endpoint using web application firewalls or network-level controls.

Implement strict input validation to prevent integer-based tenant ID enumeration. Review and audit all user roles to ensure least privilege access to tenant data.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108658. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart