PT-2026-83258 · Unknown · Springblade

·

CVE-2026-56100

·

Published

2026-08-28

·

Updated

2026-08-30

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SpringBlade versions 2.7.3 through 4.9.9
Description Authenticated attackers can escalate privileges to create system administrator accounts by sending crafted POST requests to an unprotected internal Feign user-creation endpoint exposed via @RestController that lacks authorization checks. The issue stems from a gateway authentication filter that validates JWT (JSON Web Token) parsing but fails to verify user roles or caller identity. Furthermore, a hardcoded JWT signing key embedded in publicly available JARs allows attackers to forge tokens, enabling cross-tenant data pollution and persistent backdoor access.
Recommendations Update SpringBlade to version 5.0.0 or later.

Exploit

Fix

LPE

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56100

Affected Products

Springblade