CVE-2026-108663: JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/deleteApply
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController deleteApply handler that allows any authenticated user to reject tenant administrator applications. Low-privileged attackers can send PUT requests with chosen tenantId, packId and userId values to delete pending applications in any tenant and notify applicants of rejection.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated JeecgBoot user, including a low-privileged account, can exploit it. The attacker does not need tenant-administrator privileges.
What does an attacker need to send?
The attacker must send a PUT request to /sys/tenant/deleteApply with chosen tenantId, packId, and userId values. These values can be used to target pending tenant administrator applications in other tenants.
What is the practical impact?
An attacker can reject pending tenant administrator applications and cause rejection notifications to be sent to the affected applicants. The provided information describes an integrity impact and does not indicate confidentiality or availability impact.
Which versions are affected?
JeecgBoot through version 3.9.5 is affected. The provided data does not identify a fixed version.