CVE-2026-108660
Received Received - Intake

JeecgBoot Missing Authorization in Tenant Settings

Vulnerability report for CVE-2026-108660, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to modify tenant settings by calling PUT /sys/tenant/updateApplyStatus. Low-privileged attackers can supply any tenant id to overwrite its applyStatus field, enabling or disabling tenant administrator applications across tenants.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jeecgboot JeecgBoot 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JeecgBoot through version 3.9.5 has a missing authorization vulnerability. Authenticated users can modify tenant settings by calling PUT /sys/tenant/updateApplyStatus. Low-privileged attackers can supply any tenant ID to overwrite its applyStatus field, enabling or disabling tenant administrator applications across tenants.

Detection Guidance

To detect this vulnerability, monitor HTTP PUT requests to /sys/tenant/updateApplyStatus. Check for any authenticated user modifying tenant settings without proper authorization. Review server logs for suspicious activity targeting this endpoint.

Impact Analysis

An attacker with low privileges could enable or disable tenant administrator applications for any tenant. This could disrupt tenant operations, allow unauthorized access to tenant resources, or cause denial of service by altering tenant statuses.

Compliance Impact

This vulnerability could lead to unauthorized access or modifications to tenant data, potentially violating GDPR (data protection) or HIPAA (health data privacy) by exposing sensitive information or altering access controls.

Mitigation Strategies

Immediately update JeecgBoot to version 3.9.5 or later. Implement strict access controls to restrict PUT requests to /sys/tenant/updateApplyStatus. Ensure only authorized users can modify tenant settings. Review and audit tenant configurations for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108660. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart