PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108662 jeecgboot CVE debrief

CVE-2026-108662 is a missing authorization vulnerability in JeecgBoot through version 3.9.5. Low-privileged authenticated users can remove users from tenant product packs via a PUT request to /sys/tenant/deleteTenantPackUser. Attackers can manipulate userId and packId values to remove any user from any tenant's product pack, potentially revoking permissions like tenant administrator access.

Vendor
jeecgboot
Product
Unknown
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders managing JeecgBoot instances, especially those with multi-tenancy configurations, should assess exposure and verify authorization controls to prevent unauthorized access and potential disruption of user management. This includes reviewing user management and tenant configurations, verifying authorization controls, and monitoring for suspicious activity related to user management in JeecgBoot instances.

Why it matters

CVE-2026-108662 is a missing authorization vulnerability in JeecgBoot that allows low-privileged users to remove users from tenant product packs. Defenders managing JeecgBoot instances, especially in multi-tenancy configurations, should verify authorization controls to prevent unauthorized access and potential disruption of user management.

  • Potential unauthorized revocation of tenant administrator access
  • Possible disruption of user management and permissions in multi-tenant environments
  • Need for verification of authorization controls in JeecgBoot instances

Technical summary

The vulnerability exists in the /sys/tenant/deleteTenantPackUser endpoint, allowing low-privileged users to remove users from tenant product packs by supplying arbitrary userId and packId values. This could lead to unauthorized revocation of permissions such as tenant administrator access. Defenders should prioritize verifying and restricting access to this endpoint, ensuring proper authorization checks are in place. The CVE record and NVD entry provide details on the vulnerability, but additional verification is required for exploitation, impact, and remediation.

Defensive priority

Defenders should prioritize verifying and restricting access to the /sys/tenant/deleteTenantPackUser endpoint, ensuring proper authorization checks are in place.

Recommended defensive actions

  • Verify and restrict access to the /sys/tenant/deleteTenantPackUser endpoint
  • Ensure proper authorization checks are in place for user removal from tenant product packs
  • Monitor for suspicious activity related to user management in JeecgBoot instances
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. However, the corpus does not establish versions beyond 3.9.5, exploitation, impact, or remediation, which require verification from official sources.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108662 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108662

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108662 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108662

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/JeecgBoot/poc_tenant_pack_user_removal.py

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://github.com/jeecgboot/JeecgBoot/blob/e3b9dc0aefe1943d9772b026f64ed671a7c82802/jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysTenantController.java

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/jeecgboot-through-3.9.5-missing-authorization-via-sys-tenant-deletetenantpackuser

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.