Sceawere

Vulnerability Detail

CVE-2026-108881UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

JeecgBoot Broken Access Control Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
jeecgboot
Product
JeecgBoot
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the getTenantPackInfo handler that allows any authenticated user to read other tenants' product pack membership. Low-privileged attackers can supply a tenantId and fixed packCode values such as superAdmin, accountAdmin or appAdmin to disclose administrator usernames, real names, phones and departments.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-11T15:16:55.133Z",
  "pubdate": "2026-10-11T15:16:55.133Z",
  "executiveSummary": "JeecgBoot versions up to 3.9.5 are susceptible to a missing authorization vulnerability within the getTenantPackInfo handler, categorized as a Broken Access Control issue.\nThis vulnerability allows any authenticated user, regardless of their privilege level, to perform unauthorized cross-tenant data retrieval.\nBy manipulating parameters in the request, an attacker can extract sensitive PII (Personally Identifiable Information) including usernames, real names, phone numbers, and departmental affiliations of administrative accounts associated with different tenants.\nThe primary risk implication involves mass information disclosure of organizational structures and high-privileged account data, which facilitates further targeted exploitation, such as privilege escalation or social engineering attacks.\nExploitation requires the attacker to possess an active authenticated session within the application, after which they can arbitrarily query tenant-specific membership data without further authorization checks.",
  "technicalDetails": "The vulnerability resides in the getTenantPackInfo handler within the JeecgBoot application framework, which fails to enforce strict authorization constraints when processing incoming requests.\nThe root cause is a deficiency in the access control logic, which does not validate whether the requesting user possesses the requisite permissions to access the data associated with a specific tenant identifier.\nAn attacker can exploit this by manipulating the tenantId parameter in an HTTP request targeted at the getTenantPackInfo endpoint.\nBy supplying a target tenantId along with specific, hardcoded packCode values—such as 'superAdmin', 'accountAdmin', or 'appAdmin'—the application logic bypasses standard security filters.\nThe vulnerable component processes the request by querying the backend database or service layer for records matching the provided tenantId and packCode without verifying if the user belongs to that tenant context.\nThis results in the leakage of sensitive administrative records, including full names, contact information, and departmental data associated with the requested packCode.\nThe attack flow is as follows: 1) The attacker authenticates as a standard, low-privileged user; 2) The attacker identifies the getTenantPackInfo endpoint; 3) The attacker crafts a request, injecting arbitrary tenantId values and valid packCode constants; 4) The application, failing to perform server-side authorization checks, returns the requested PII in the JSON response; 5) The attacker repeats this process for multiple tenantId values to harvest sensitive data across the platform.\nThe impact is significant, as it enables an attacker to map the administrative hierarchy of the entire platform, potentially identifying targets for credential stuffing or phishing campaigns. The vulnerability persists across all versions of JeecgBoot up to and including 3.9.5, necessitating a comprehensive review of the authorization middleware governing the tenant management module."
}
CVE-2026-108881: JeecgBoot Broken Access Control Vulnerability (MEDIUM Severity, CVSS: 4.3) | Sceawere