Sceawere
Vulnerability Detail
CVE-2026-108876UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
JeecgBoot Missing Authorization Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 3h ago
- Vendor
- jeecgboot
- Product
- JeecgBoot
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the putCancelQuit handler of SysUserController, allowing any authenticated user to cancel user resignations. Low-privileged attackers can supply user ids and a tenantId parameter or X-Tenant-Id header to restore ended, pending, or refused tenant memberships to normal.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-11T15:16:54.463Z",
"pubdate": "2026-10-11T15:16:54.463Z",
"executiveSummary": "A missing authorization vulnerability exists within JeecgBoot through version 3.9.5, located in the putCancelQuit handler of the SysUserController component. This flaw allows any authenticated user, regardless of their assigned authorization level, to execute actions that alter tenant membership statuses across the application. An attacker possessing low-privileged access can supply target user identifiers along with a tenantId parameter or an X-Tenant-Id HTTP header to forcibly restore tenant memberships that were previously in ended, pending, or refused states back to normal status.\nThe risk implications of this vulnerability include unauthorized privilege reinstatement, breach of tenant isolation controls, and corruption of organizational user lifecycle management. Exploitation requires standard network exposure and valid user authentication, but demands no elevated administrative privileges or complex interactions. By exploiting this access control failure, low-privileged users can unilaterally override management decisions and re-establish unauthorized tenant access within affected JeecgBoot deployments.",
"technicalDetails": "The root cause of this vulnerability lies in missing authorization enforcement within the putCancelQuit request handler implemented inside SysUserController. In JeecgBoot applications up through version 3.9.5, the backend relies on authentication mechanisms to identify the requesting entity but fails to implement adequate functional or object-level authorization checks before modifying tenant relationship records in the database.\nThe vulnerable component, SysUserController, processes user management actions, including account resignation reversals. When a request reaches the putCancelQuit handler, the application extracts target user identifiers alongside tenant context parameters. However, it omits validating whether the authenticated user holds administrative rights over the specified tenant or has explicit permission to alter user status records. The tenant context can be dictated by the client through either a standard HTTP request parameter named tenantId or via a custom request header named X-Tenant-Id.\nExploitation proceeds through a structured attack flow. First, an attacker authenticates to the JeecgBoot application using a low-privileged user account to establish a valid session context. Second, the attacker crafts an HTTP request targeting the putCancelQuit handler within SysUserController. Third, the attacker inserts target user IDs into the payload and sets the target tenant context using either the tenantId request parameter or the X-Tenant-Id HTTP header. Fourth, the application processes the incoming request, authenticates the session, and directly executes the database update logic without evaluating authorization policies. Fifth, the application updates the targeted user records, transitioning tenant memberships from ended, pending, or refused statuses back to an active normal state.\nThe post-exploitation impact allows low-privileged attackers to subvert enterprise governance, re-enable revoked account access, bypass multi-tenant boundaries, and restore access for users whose access was previously rejected or terminated. This functional authorization bypass compromises data segregation and user identity management across multi-tenant environments."
}