PatchSiren cyber security CVE debrief
CVE-2026-108659 jeecgboot CVE debrief
CVE-2026-108659 is a missing authorization vulnerability in JeecgBoot through 3.9.5, specifically in the SysTenantController listPackByTenantUserId handler. This allows any authenticated user to query tenant product packs by supplying arbitrary tenantId and userId parameters, potentially revealing which users are tenant administrators and exposing sensitive configuration information. Defenders should assess exposure and prioritize mitigation, especially in multi-tenant environments, to prevent potential enumeration of tenant product pack configurations and revelation of tenant administrator users.
- Vendor
- jeecgboot
- Product
- Unknown
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for systems using JeecgBoot, especially those with multi-tenant configurations, should assess exposure and prioritize mitigation to prevent potential enumeration of tenant product pack configurations and revelation of tenant administrator users. They should also review compensating controls and monitor for potential exploitation attempts.
Why it matters
CVE-2026-108659 is a missing authorization vulnerability in JeecgBoot that allows authenticated users to query tenant product packs, potentially revealing sensitive configuration information and tenant administrator users. Defenders should prioritize verification and mitigation, especially in multi-tenant environments.
- Potential enumeration of tenant product pack configurations
- Possible revelation of tenant administrator users
- Increased risk of targeted attacks due to information disclosure
- Need for verification of JeecgBoot version and exposure
Technical summary
The vulnerability exists in the SysTenantController listPackByTenantUserId handler of JeecgBoot through 3.9.5. An authenticated user can exploit this by supplying arbitrary tenantId and userId parameters to enumerate any tenant's product pack configuration and potentially reveal which users are tenant administrators. This could lead to increased risk of targeted attacks due to information disclosure. Defenders should prioritize verifying and mitigating this vulnerability, especially in systems where tenant product pack configurations may contain sensitive information.
Defensive priority
Defenders should prioritize verifying and mitigating this vulnerability, especially in systems where tenant product pack configurations may contain sensitive information.
Recommended defensive actions
- Verify the version of JeecgBoot being used and assess exposure
- Restrict access to the SysTenantController listPackByTenantUserId handler
- Implement proper authorization checks for querying tenant product packs
- Monitor for potential exploitation attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD entry provide details about the vulnerability, but additional information from the vendor and other sources may be necessary to fully understand the impact and mitigate the vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108659 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108659
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108659 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108659
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/JeecgBoot/poc_tenant_pack_by_user.py
-
Source reference
Unverified legacy reference
URL: https://github.com/jeecgboot/JeecgBoot/blob/e3b9dc0aefe1943d9772b026f64ed671a7c82802/jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysTenantController.java
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/jeecgboot-through-3.9.5-missing-authorization-via-sys-tenant-listpackbytenantuserid
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.