CVE-2026-108659 | Jeecg JeecgBoot up to 3.9.5 Tenant Pack poc_tenant_pack_by_user.py SysTenantController.listPackByTenantUserId tenantId/userId improper authorization
A vulnerability, which was classified as problematic, has been found in Jeecg JeecgBoot up to 3.9.5. The impacted element is the function SysTenantController.listPackByTenantUserId of the file poc_tenant_pack_by_user.py of the component Tenant Pack Handler. Performing a manipulation of the argument tenantId/userId results in improper authorization.
This vulnerability is known as CVE-2026-108659. Remote exploitation of the attack is possible. No exploit is available.VulDB Recent EntriesRead More