CVE-2026-108661
Received Received - Intake

JeecgBoot Missing Authorization in Tenant Ownership Transfer

Vulnerability report for CVE-2026-108661, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to transfer tenant ownership via POST /sys/tenant/changeOwenUserTenant. Low-privileged attackers can supply userId and tenantId parameters to reassign any tenant's owner to a member, including themselves, and strip the legitimate owner.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jeecgboot JeecgBoot 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JeecgBoot through version 3.9.5 has a missing authorization vulnerability. This flaw allows any authenticated user to transfer ownership of a tenant by sending a POST request to /sys/tenant/changeOwenUserTenant with userId and tenantId parameters. Attackers can reassign any tenant's owner to another user, including themselves, effectively removing the legitimate owner.

Detection Guidance

Check for unauthorized POST requests to /sys/tenant/changeOwenUserTenant with userId and tenantId parameters. Monitor logs for unexpected tenant ownership changes or low-privileged users gaining owner privileges.

Impact Analysis

Low-privileged attackers could gain control over tenant resources, leading to unauthorized access, data manipulation, or disruption of services. This could result in loss of administrative control, potential data breaches, or unauthorized changes to tenant configurations.

Compliance Impact

This vulnerability could lead to unauthorized access or modification of sensitive data, violating confidentiality and integrity requirements in GDPR and HIPAA. Organizations using affected JeecgBoot versions may face compliance violations, legal penalties, and reputational damage due to potential data exposure or loss of control over tenant data.

Mitigation Strategies

Apply the latest JeecgBoot patch to version 3.9.5 or higher. Restrict access to the /sys/tenant/changeOwenUserTenant endpoint. Review and audit tenant ownership changes for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108661. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart