Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-108661

MEDIUM NVD
CVSS Score 6.5
Severity MEDIUM
Published Oct 10, 2026
Vendor unknown

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to transfer tenant ownership via POST /sys/tenant/changeOwenUserTenant. Low-privileged attackers can supply userId and tenantId parameters to reassign any tenant's owner to a member, including themselves, and strip the legitimate owner.

References