PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108661 jeecgboot CVE debrief

CVE-2026-108661 is a missing authorization vulnerability in JeecgBoot through version 3.9.5. This vulnerability allows any authenticated user to transfer tenant ownership. Low-privileged attackers can exploit this by supplying userId and tenantId parameters to reassign any tenant's owner to a member, including themselves, and strip the legitimate owner. The vulnerability exists in the SysTenantController class, specifically in the changeOwenUserTenant method. Defenders should assess exposure and prioritize remediation, especially in systems where tenant ownership management is critical. Verification of affected versions and remediation steps is necessary to prevent potential misuse

Vendor
jeecgboot
Product
Unknown
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders responsible for JeecgBoot installations, especially those with tenant ownership management, should assess exposure and prioritize remediation. They should review compensating controls for exposed systems while remediation is scheduled and verified. Defenders should also track exceptions, retest remediated assets, and close the item only after evidence is documented

Why it matters

CVE-2026-108661 is a high-severity vulnerability in JeecgBoot that allows authenticated users to transfer tenant ownership, potentially leading to privilege escalation and unauthorized access.

  • Authenticated users can transfer tenant ownership without proper authorization
  • Low-privileged attackers can exploit this to gain elevated privileges
  • Tenant ownership changes can be made without legitimate owner's consent
  • Verification of affected versions and remediation steps is necessary

Technical summary

The vulnerability exists in the SysTenantController class, specifically in the changeOwenUserTenant method. This method allows any authenticated user to transfer tenant ownership by supplying userId and tenantId parameters. The vulnerability allows authenticated users to transfer tenant ownership without proper authorization, potentially leading to privilege escalation and unauthorized access. Defenders should prioritize verifying and remediating this vulnerability, especially in systems where tenant ownership management is critical. Verification of affected versions and remediation steps is necessary to prevent potential misuse

Defensive priority

Defenders should prioritize verifying and remediating this vulnerability, especially in systems where tenant ownership management is critical.

Recommended defensive actions

  • Verify and remediate the vulnerability in JeecgBoot installations
  • Restrict access to tenant ownership management
  • Monitor for suspicious tenant ownership changes
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide details about the vulnerability. Additional verification is needed to confirm affected versions and remediation steps. The vulnerability allows authenticated users to transfer tenant ownership without proper authorization, potentially leading to privilege escalation and unauthorized access. Defenders should verify and remediate this vulnerability, especially in systems where tenant ownership management is critical. The CVE Program record and NVD detail page offer source-provided CVE metadata and a

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108661 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108661

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108661 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108661

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/JeecgBoot/poc_tenant_change_owner.py

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://github.com/jeecgboot/JeecgBoot/blob/e3b9dc0aefe1943d9772b026f64ed671a7c82802/jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysTenantController.java

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/jeecgboot-through-3.9.5-missing-authorization-via-sys-tenant-changeowenusertenant

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.