CVE-2026-108662
Received Received - Intake

Missing Authorization in JeecgBoot Allows User Removal

Vulnerability report for CVE-2026-108662, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to remove users from tenant product packs via PUT /sys/tenant/deleteTenantPackUser. Attackers can supply arbitrary userId and packId values in the request body to remove any user from any tenant's product pack, revoking permissions such as tenant administrator access.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jeecgboot JeecgBoot 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JeecgBoot through version 3.9.5 has a missing authorization vulnerability. Low-privileged authenticated users can exploit this by sending a PUT request to /sys/tenant/deleteTenantPackUser to remove users from tenant product packs. Attackers can specify any userId and packId in the request body to revoke permissions, such as removing a user's tenant administrator access.

Detection Guidance

To detect this vulnerability, monitor HTTP PUT requests to /sys/tenant/deleteTenantPackUser with arbitrary userId and packId values. Check logs for unauthorized user removal events or permission revocations in JeecgBoot versions up to 3.9.5.

Impact Analysis

This vulnerability allows attackers with low privileges to remove users from tenant product packs, potentially revoking critical permissions like tenant administrator access. This could lead to unauthorized privilege reduction, disrupting normal operations or causing denial of service for affected users.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized privilege changes, potentially violating access control requirements in GDPR and HIPAA. Unauthorized removal of users may lead to improper data access or loss of audit trails, increasing non-compliance risks.

Mitigation Strategies

Upgrade JeecgBoot to a version beyond 3.9.5 where the vulnerability is patched. Implement strict access controls to restrict PUT requests to authorized endpoints only. Review logs for suspicious activity related to user removal or permission changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108662. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart