PatchSiren cyber security CVE debrief
CVE-2026-108658 jeecgboot CVE debrief
CVE-2026-108658 is a missing authorization vulnerability in JeecgBoot through version 3.9.5, specifically in the SysTenantController queryTenantAuthInfo handler. This allows any authenticated user to read other tenants' records. Low-privileged attackers can exploit this by iterating small integer tenant IDs to retrieve full sys_tenant records, including sensitive information like house numbers used as tenant join codes and company profile fields.
- Vendor
- jeecgboot
- Product
- Unknown
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for JeecgBoot instances, security teams monitoring for potential exploitation attempts, and administrators ensuring proper authorization checks are in place should be aware of this vulnerability and take necessary actions to mitigate it.
Why it matters
CVE-2026-108658 is a missing authorization vulnerability in JeecgBoot that allows authenticated users to read other tenants' records. Defenders should prioritize verifying and patching vulnerable instances, ensuring proper authorization checks, and monitoring for exploitation attempts. The vulnerability's impact is primarily related to potential exposure of sensitive information and the need for swift remediation.
- Potential exposure of sensitive tenant information, including house numbers and company profile fields.
- Ability for low-privileged attackers to iterate tenant IDs and retrieve full sys_tenant records.
- Need for defenders to verify and patch vulnerable JeecgBoot instances to prevent unauthorized access.
- Importance of monitoring for potential exploitation attempts and reviewing system logs for suspicious activity.
Technical summary
The vulnerability exists in the SysTenantController queryTenantAuthInfo handler of JeecgBoot through version 3.9.5. It allows any authenticated user to read other tenants' records by iterating small integer tenant IDs. This can lead to exposure of sensitive information such as house numbers used as tenant join codes and company profile fields. Defenders should prioritize verifying and patching vulnerable JeecgBoot instances, ensuring proper authorization checks are in place, and monitoring for potential exploitation attempts to mitigate the impact of this vulnerability.
Defensive priority
Defenders should prioritize verifying and patching vulnerable JeecgBoot instances, ensuring proper authorization checks are in place, and monitoring for potential exploitation attempts.
Recommended defensive actions
- Verify and patch vulnerable JeecgBoot instances to prevent unauthorized access to tenant records.
- Ensure proper authorization checks are in place for the SysTenantController queryTenantAuthInfo handler.
- Monitor for potential exploitation attempts and review system logs for suspicious activity.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description and CVSS score. However, the corpus lacks specific information on affected versions, exploitation, or remediation beyond patching.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108658 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108658
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108658 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108658
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/JeecgBoot/poc_tenant_ownership_and_pack_approval.py
-
Source reference
Unverified legacy reference
URL: https://github.com/jeecgboot/JeecgBoot/blob/e3b9dc0aefe1943d9772b026f64ed671a7c82802/jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysTenantController.java
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/jeecgboot-through-3.9.5-missing-authorization-via-sys-tenant-querytenantauthinfo
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.