CVE-2026-108657: JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/passApply
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController passApply handler that allows any authenticated user to approve tenant administrator applications. Attackers can file a pending application via doApplyTenantPackUser and approve it through PUT /sys/tenant/passApply to gain tenant administrator pack permissions in any tenant.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated JeecgBoot user can exploit it. The attacker does not need existing tenant administrator privileges.
What does an attacker need to do to gain the elevated permissions?
The attacker can submit a pending tenant administrator application through doApplyTenantPackUser, then approve that application by sending a PUT request to /sys/tenant/passApply. This grants tenant administrator pack permissions in any tenant.
Are deployments through version 3.9.5 affected?
The affected range is JeecgBoot through version 3.9.5. The provided information does not identify a fixed version or a configuration-based exception.