


Perceptive Security
SOC/SIEM Consultancy

SpringBlade versions 2.7.3 through 3.5.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator account…
Published:
28 augustus 2026 om 00:00:00
Alert date:
28 augustus 2026 om 23:18:32
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications, Identity & Access
SpringBlade versions 2.7.3 through 3.5.0 are affected by a privilege escalation vulnerability tracked as CVE-2026-56100. Authenticated attackers can exploit an unprotected internal Feign user-creation endpoint exposed via @RestController without authorization checks to create system administrator accounts. The gateway's authentication filter only validates JWT parsing without verifying user roles or caller identity, making it insufficient as a security control. A hardcoded JWT signing key embedded in publicly available JARs allows attackers to forge valid tokens and escalate privileges from low-privilege user to administrator. Successful exploitation enables cross-tenant data pollution and persistent backdoor access. The vulnerability affects a widely used Java microservices framework. A fix is available in SpringBlade v5.0.0 as indicated by the referenced commit and release notes.
Technical details
Mitigation steps:
Affected products:
SpringBlade 2.7.3
SpringBlade 3.5.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-56100
https://gist.github.com/sud0why/e73405057dd7414a8c221ef17e0d0059#file-cve-2026-56100-springblade-authbypass-en-md
https://github.com/chillzhuang/SpringBlade
https://github.com/chillzhuang/SpringBlade/commit/c69b9547c942c697da2f3ee6a9265b6004abd645
https://github.com/chillzhuang/SpringBlade/releases#release-v5.0.0
https://www.vulncheck.com/advisories/springblade-privilege-escalation-via-exposed-feign-endpoint
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
