JeecgBoot low-code platform: 76 missing-authorisation CVEs in 3.9.5 and earlier let any logged-in user approve tenant admin rights, rewrite role permissions or pull decrypted database passwords and AI MCP tokens (top CVSS 4.0 8.6); no fixed release yet
VulnCheck, acting as CVE numbering authority, published 76 CVE records (CVE-2026-108605 to CVE-2026-108680) on 10 October 2026 for missing or broken authorisation checks in JeecgBoot, the open-source Java and Vue low-code development platform from Jeecg widely used for internal business systems in China and elsewhere. All affect JeecgBoot through 3.9.5, the latest release (27 August 2026). Each lets a low-privileged authenticated user call an administrative endpoint that lacks a Shiro permission or role check. The two highest, rated CVSS 4.0 8.6 and CVSS 3.1 8.1, are CVE-2026-108657, where any user can approve their own pending tenant administrator application through PUT /sys/tenant/passApply and gain tenant admin permissions in any tenant, and CVE-2026-108628, where any user can grant arbitrary menu and button permissions through the saveDeptRolePermission endpoint. Others rated 7.1 include CVE-2026-108648, which returns JDBC URLs, usernames and decrypted cleartext database passwords from /sys/api/getDynamicDbSourceByCode, CVE-2026-108671, which exposes AI (airag) MCP server endpoint URLs, headers and outbound authentication tokens because a permission check is commented out, and CVE-2026-108661, which transfers ownership of any tenant. Many of the rest let users read or change announcements, logs, tenant settings and AI prompt records, scored 4.3 to 5.4. Credited researchers include Yaqi Chao, and public proof-of-concept scripts are linked from the CVE records. No fixed version is listed and no exploitation has been reported. Primary: VulnCheck advisories; CVE records.
- Product
- JeecgBoot (Jeecg) — open-source Java/Vue low-code development platform, including its airag AI module
- Versions
- 3.9.5 and earlier
- CVSS
- Up to (CVSS 4.0) / 8.1 (CVSS 3.1) for CVE-2026-108657 and CVE-2026-108628; several at 7.1; most 4.3–5.4 (VulnCheck)
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N - Exploited in Australia?
- unknown
- Patch to
- No fixed release yet; watch the JeecgBoot GitHub releases. Meanwhile keep JeecgBoot off the internet or behind a VPN or reverse proxy that blocks /sys/tenant, /sys/api and /airag paths for ordinary users, close self-registration, rotate database passwords and MCP or AI tokens configured in the platform, and review tenant owners and role permissions for unexpected changes.
Primary: VulnCheck — JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/passApply (CVE-2026-108657); one of 76 advisories · Vendor: JeecgBoot releases on GitHub (latest v3.9.5, 27 Aug 2026) · CVE: CVE-2026-108605, CVE-2026-108680, CVE-2026-108657, CVE-2026-108628, CVE-2026-108648, CVE-2026-108671, CVE-2026-108661 · CVE-2026-108648 — JeecgBoot getDynamicDbSourceByCode returns decrypted database passwords (VulnCheck CNA, 10 Oct 2026)
