PatchSiren cyber security CVE debrief
CVE-2026-108661 jeecgboot CVE debrief
CVE-2026-108661 is a missing authorization vulnerability in JeecgBoot through version 3.9.5. This vulnerability allows any authenticated user to transfer tenant ownership. Low-privileged attackers can exploit this by supplying userId and tenantId parameters to reassign any tenant's owner to a member, including themselves, and strip the legitimate owner. The vulnerability exists in the SysTenantController class, specifically in the changeOwenUserTenant method. Defenders should assess exposure and prioritize remediation, especially in systems where tenant ownership management is critical. Verification of affected versions and remediation steps is necessary to prevent potential misuse
- Vendor
- jeecgboot
- Product
- Unknown
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for JeecgBoot installations, especially those with tenant ownership management, should assess exposure and prioritize remediation. They should review compensating controls for exposed systems while remediation is scheduled and verified. Defenders should also track exceptions, retest remediated assets, and close the item only after evidence is documented
Why it matters
CVE-2026-108661 is a high-severity vulnerability in JeecgBoot that allows authenticated users to transfer tenant ownership, potentially leading to privilege escalation and unauthorized access.
- Authenticated users can transfer tenant ownership without proper authorization
- Low-privileged attackers can exploit this to gain elevated privileges
- Tenant ownership changes can be made without legitimate owner's consent
- Verification of affected versions and remediation steps is necessary
Technical summary
The vulnerability exists in the SysTenantController class, specifically in the changeOwenUserTenant method. This method allows any authenticated user to transfer tenant ownership by supplying userId and tenantId parameters. The vulnerability allows authenticated users to transfer tenant ownership without proper authorization, potentially leading to privilege escalation and unauthorized access. Defenders should prioritize verifying and remediating this vulnerability, especially in systems where tenant ownership management is critical. Verification of affected versions and remediation steps is necessary to prevent potential misuse
Defensive priority
Defenders should prioritize verifying and remediating this vulnerability, especially in systems where tenant ownership management is critical.
Recommended defensive actions
- Verify and remediate the vulnerability in JeecgBoot installations
- Restrict access to tenant ownership management
- Monitor for suspicious tenant ownership changes
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD entry provide details about the vulnerability. Additional verification is needed to confirm affected versions and remediation steps. The vulnerability allows authenticated users to transfer tenant ownership without proper authorization, potentially leading to privilege escalation and unauthorized access. Defenders should verify and remediate this vulnerability, especially in systems where tenant ownership management is critical. The CVE Program record and NVD detail page offer source-provided CVE metadata and a
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108661 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108661
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108661 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108661
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/JeecgBoot/poc_tenant_change_owner.py
-
Source reference
Unverified legacy reference
URL: https://github.com/jeecgboot/JeecgBoot/blob/e3b9dc0aefe1943d9772b026f64ed671a7c82802/jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysTenantController.java
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/jeecgboot-through-3.9.5-missing-authorization-via-sys-tenant-changeowenusertenant
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.