PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108659 jeecgboot CVE debrief

CVE-2026-108659 is a missing authorization vulnerability in JeecgBoot through 3.9.5, specifically in the SysTenantController listPackByTenantUserId handler. This allows any authenticated user to query tenant product packs by supplying arbitrary tenantId and userId parameters, potentially revealing which users are tenant administrators and exposing sensitive configuration information. Defenders should assess exposure and prioritize mitigation, especially in multi-tenant environments, to prevent potential enumeration of tenant product pack configurations and revelation of tenant administrator users.

Vendor
jeecgboot
Product
Unknown
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders responsible for systems using JeecgBoot, especially those with multi-tenant configurations, should assess exposure and prioritize mitigation to prevent potential enumeration of tenant product pack configurations and revelation of tenant administrator users. They should also review compensating controls and monitor for potential exploitation attempts.

Why it matters

CVE-2026-108659 is a missing authorization vulnerability in JeecgBoot that allows authenticated users to query tenant product packs, potentially revealing sensitive configuration information and tenant administrator users. Defenders should prioritize verification and mitigation, especially in multi-tenant environments.

  • Potential enumeration of tenant product pack configurations
  • Possible revelation of tenant administrator users
  • Increased risk of targeted attacks due to information disclosure
  • Need for verification of JeecgBoot version and exposure

Technical summary

The vulnerability exists in the SysTenantController listPackByTenantUserId handler of JeecgBoot through 3.9.5. An authenticated user can exploit this by supplying arbitrary tenantId and userId parameters to enumerate any tenant's product pack configuration and potentially reveal which users are tenant administrators. This could lead to increased risk of targeted attacks due to information disclosure. Defenders should prioritize verifying and mitigating this vulnerability, especially in systems where tenant product pack configurations may contain sensitive information.

Defensive priority

Defenders should prioritize verifying and mitigating this vulnerability, especially in systems where tenant product pack configurations may contain sensitive information.

Recommended defensive actions

  • Verify the version of JeecgBoot being used and assess exposure
  • Restrict access to the SysTenantController listPackByTenantUserId handler
  • Implement proper authorization checks for querying tenant product packs
  • Monitor for potential exploitation attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and NVD entry provide details about the vulnerability, but additional information from the vendor and other sources may be necessary to fully understand the impact and mitigate the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108659 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108659

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108659 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108659

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/JeecgBoot/poc_tenant_pack_by_user.py

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://github.com/jeecgboot/JeecgBoot/blob/e3b9dc0aefe1943d9772b026f64ed671a7c82802/jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysTenantController.java

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/jeecgboot-through-3.9.5-missing-authorization-via-sys-tenant-listpackbytenantuserid

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.