CVE-2026-108881: JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/getTenantPackInfo
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the getTenantPackInfo handler that allows any authenticated user to read other tenants' product pack membership. Low-privileged attackers can supply a tenantId and fixed packCode values such as superAdmin, accountAdmin or appAdmin to disclose administrator usernames, real names, phones and departments.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated JeecgBoot user, including a low-privileged account, can exploit it. The attacker does not need user interaction and can access data belonging to other tenants.
What information can be exposed?
An attacker can provide another tenant's tenantId together with fixed administrative packCode values such as superAdmin, accountAdmin, or appAdmin. The response can disclose administrator usernames, real names, phone numbers, and departments.
Are unauthenticated systems affected?
The vulnerable handler requires authentication, so an unauthenticated attacker is not described as able to exploit it directly. Environments where low-privileged users can authenticate remain exposed.
How can I check whether the issue is present?
JeecgBoot versions through 3.9.5 are affected. In an authorized test, authenticate as a low-privileged user and determine whether /sys/tenant/getTenantPackInfo returns another tenant's administrative pack membership when supplied with that tenant's tenantId and an administrative packCode.