Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-108657

HIGH NVD
CVSS Score 8.1
Severity HIGH
Published Oct 10, 2026
Vendor unknown

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController passApply handler that allows any authenticated user to approve tenant administrator applications. Attackers can file a pending application via doApplyTenantPackUser and approve it through PUT /sys/tenant/passApply to gain tenant administrator pack permissions in any tenant.

References