← Back to the live CVE advisory feed

CVE-2026-108657: Product identification pending

Severity
8.6 (HIGH)
Vendor
JEECGBOOT THROUGH
Affected versions
Through 3.9.5
Patch status
Unknown
Published
2026-10-10T22:16:41.923
Modified
2026-10-10T22:16:41.923

Why it matters

High-severity vulnerability requiring prioritized review.

Recommended admin actions

  • Review and patch based on exposure, asset criticality, and business impact.
  • Compare installed versions against the affected version range in the advisory.

Technical summary

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController passApply handler that allows any authenticated user to approve tenant administrator applications. Attackers can file a pending application via doApplyTenantPackUser and approve it through PUT /sys/tenant/passApply to gain tenant administrator pack permissions in any tenant.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: OCT 11, 2026 12:00 PM UTC
352 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-42696
SiteVault – Backup, Restore, Migration & Cloning
Reporter: AUDIT
10
CRITICAL
VIEW RECORD
CVE-2026-62024
CodeBard Help Desk
Reporter: AUDIT
9.9
CRITICAL
VIEW RECORD
CVE-2026-62129
Creator LMS PATCH
Reporter: AUDIT
9.9
CRITICAL
VIEW RECORD
CVE-2026-104398
AFFI – Affiliate Marketing for WooCommerce PATCH
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-105892
rtMedia for WordPress, BuddyPress and bbPress PATCH
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-106610
miniorange otp verification PATCH
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-39801
AIWU
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-42716
Payever – WooCommerce Gateway
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-42718
Booster for WooCommerce PATCH
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-42719
Dynamic User Directory
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-42723
CleanSkin
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-62022
Tonda Membership
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-62032
DirectoryPress
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-62050
Splendour
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-62051
Stargaze
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-62052
Tipsy
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-62053
Wine House
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-62054
Yacht Rental
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-62076
Kalles
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-62077
Avala
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-62086
Juno
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-62087
Equadio
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-62090
WineShop
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-62120
Law Office
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-62123
Invetex
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-62124
N7 | Golf Club Sports & Events
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-62125
Asia Garden
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-66482
Drone Media
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-66483
Education Center
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-66563
Windsor
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-66564
ShiftCV
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-66565
FC United
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-66567
Anesta
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-66568
Original
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-66569
Kicker
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-78529
Alliance
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-78531
Jacqueline
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-78533
Qwery
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-78535
Photolia
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-81797
Buzz Stone | Magazine & Viral Blog WordPress Theme
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-108551
openapi-typescript-codegen
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-105889
Tickera PATCH
Reporter: AUDIT
9.3
CRITICAL
VIEW RECORD
CVE-2026-108598
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-40800
ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes
Reporter: AUDIT
9.3
CRITICAL
VIEW RECORD
CVE-2026-62031
uListing
Reporter: AUDIT
9.3
CRITICAL
VIEW RECORD
CVE-2026-108707
Wukong_HRM
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-108549
Product identification pending
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-62025
Tailored Tools
Reporter: AUDIT
9
CRITICAL
VIEW RECORD
CVE-2026-105885
Product identification pending
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-62021
Angio
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-108550
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-108708
Wukong_HRM
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-108628
Product identification pending
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-108657
Product identification pending
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-108540
Spug
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-42633
Events Manager PATCH
Reporter: AUDIT
8.5
HIGH
VIEW RECORD
CVE-2026-42712
Qode Tours
Reporter: AUDIT
8.5
HIGH
VIEW RECORD
CVE-2026-62117
Barcode Scanner with Inventory & Order Manager PATCH
Reporter: AUDIT
8.5
HIGH
VIEW RECORD
CVE-2026-108545
Product identification pending
Reporter: DISCLOSURE
8.2
HIGH
VIEW RECORD
CVE-2026-96341
Product identification pending
Reporter: AUDIT
8.2
HIGH
VIEW RECORD
CVE-2026-39802
Everest Backup
Reporter: AUDIT
8.1
HIGH
VIEW RECORD
CVE-2026-40777
WPSection
Reporter: AUDIT
8.1
HIGH
VIEW RECORD
CVE-2026-40801
Wordable
Reporter: AUDIT
8.1
HIGH
VIEW RECORD
CVE-2026-42704
Kids Care
Reporter: AUDIT
8.1
HIGH
VIEW RECORD
CVE-2026-42724
CleanSkin
Reporter: AUDIT
8.1
HIGH
VIEW RECORD
CVE-2026-42777
Aalto
Reporter: AUDIT
8.1
HIGH
VIEW RECORD
CVE-2026-48193
Uminex
Reporter: AUDIT
8.1
HIGH
VIEW RECORD
CVE-2026-48194
DukaMarket
Reporter: AUDIT
8.1
HIGH
VIEW RECORD
CVE-2026-62020
TouchUp PATCH
Reporter: AUDIT
8.1
HIGH
VIEW RECORD
CVE-2026-62065
Cardea
Reporter: AUDIT
8.1
HIGH
VIEW RECORD
CVE-2026-62066
Volos
Reporter: AUDIT
8.1
HIGH
VIEW RECORD
CVE-2026-62067
Kaven
Reporter: AUDIT
8.1
HIGH
VIEW RECORD
CVE-2026-62068
Teoro
Reporter: AUDIT
8.1
HIGH
VIEW RECORD
CVE-2026-62069
Fabius
Reporter: AUDIT
8.1
HIGH
VIEW RECORD
CVE-2026-62070
Flipmart
Reporter: AUDIT
8.1
HIGH
VIEW RECORD
CVE-2026-62074
Ozeum
Reporter: AUDIT
8.1
HIGH
VIEW RECORD
CVE-2026-62075
Backhoe
Reporter: AUDIT
8.1
HIGH
VIEW RECORD
CVE-2026-62092
Armania
Reporter: AUDIT
8.1
HIGH
VIEW RECORD
CVE-2026-62094
TechOne
Reporter: AUDIT
8.1
HIGH
VIEW RECORD
CVE-2026-62096
Biolife
Reporter: AUDIT
8.1
HIGH
VIEW RECORD
CVE-2026-62099
Boutique
Reporter: AUDIT
8.1
HIGH
VIEW RECORD
CVE-2026-62115
Product identification pending
Reporter: AUDIT
8.1
HIGH
VIEW RECORD
CVE-2026-66566
Product identification pending
Reporter: AUDIT
8.1
HIGH
VIEW RECORD
CVE-2026-108161
Product identification pending
Reporter: DISCLOSURE
7.7
HIGH
VIEW RECORD
CVE-2026-108546
Product identification pending
Reporter: DISCLOSURE
7.7
HIGH
VIEW RECORD
CVE-2026-108553
Product identification pending
Reporter: DISCLOSURE
7.7
HIGH
VIEW RECORD
CVE-2026-40805
Product identification pending
Reporter: AUDIT
7.7
HIGH
VIEW RECORD
CVE-2026-78530
Product identification pending
Reporter: AUDIT
7.7
HIGH
VIEW RECORD
CVE-2026-40802
Product identification pending
Reporter: AUDIT
7.6
HIGH
VIEW RECORD
CVE-2026-42717
Product identification pending
Reporter: AUDIT
7.6
HIGH
VIEW RECORD
CVE-2026-42722
Product identification pending
Reporter: AUDIT
7.6
HIGH
VIEW RECORD
CVE-2026-45440
Product identification pending
Reporter: AUDIT
7.6
HIGH
VIEW RECORD
CVE-2026-62033
Product identification pending
Reporter: AUDIT
7.6
HIGH
VIEW RECORD
CVE-2026-103071
Product identification pending
Reporter: AUDIT
7.5
HIGH
VIEW RECORD
CVE-2026-106609
Product identification pending
Reporter: AUDIT
7.5
HIGH
VIEW RECORD
CVE-2026-42630
Product identification pending
Reporter: AUDIT
7.5
HIGH
VIEW RECORD
CVE-2026-42705
Product identification pending
Reporter: AUDIT
7.5
HIGH
VIEW RECORD
CVE-2026-42706
Product identification pending
Reporter: AUDIT
7.5
HIGH
VIEW RECORD
CVE-2026-62043
Product identification pending
Reporter: AUDIT
7.5
HIGH
VIEW RECORD
CVE-2026-65459
Product identification pending
Reporter: AUDIT
7.5
HIGH
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.