top of page
perceptive_background_267k.jpg

SpringBlade versions 2.7.3 through 3.5.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator account…

Published:

28 augustus 2026 om 00:00:00

Alert date:

28 augustus 2026 om 23:18:32

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications, Identity & Access

SpringBlade versions 2.7.3 through 3.5.0 are affected by a privilege escalation vulnerability tracked as CVE-2026-56100. Authenticated attackers can exploit an unprotected internal Feign user-creation endpoint exposed via @RestController without authorization checks to create system administrator accounts. The gateway's authentication filter only validates JWT parsing without verifying user roles or caller identity, making it insufficient as a security control. A hardcoded JWT signing key embedded in publicly available JARs allows attackers to forge valid tokens and escalate privileges from low-privilege user to administrator. Successful exploitation enables cross-tenant data pollution and persistent backdoor access. The vulnerability affects a widely used Java microservices framework. A fix is available in SpringBlade v5.0.0 as indicated by the referenced commit and release notes.

Technical details

Mitigation steps:

Affected products:

SpringBlade 2.7.3
SpringBlade 3.5.0

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page