Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 28 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SpringBlade versions 2.7.3 through 3.5.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by sending crafted POST requests to an unprotected internal Feign user-creation endpoint exposed via @RestController without authorization checks. Attackers can exploit the gateway's authentication filter, which only validates JWT parsing without verifying user roles or caller identity, and leverage a hardcoded JWT signing key embedded in publicly available JARs to forge tokens and escalate privileges from a low-privilege user to administrator, enabling cross-tenant data pollution and persistent backdoor access. | |
| Title | SpringBlade 2.7.3 < 5.0.0 Privilege Escalation via Exposed Feign Endpoint | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-28T20:30:10.433Z
Reserved: 2026-06-18T19:15:10.649Z
Link: CVE-2026-56100
No data.
Status : Received
Published: 2026-08-28T20:18:30.640
Modified: 2026-08-28T20:18:30.640
Link: CVE-2026-56100
No data.
OpenCVE Enrichment
Updated: 2026-08-28T21:30:05Z
-
CWE-862
Missing Authorization