CVE-2026-56100
W SpringBlade występuje luka eskalacji uprawnień, umożliwiająca tworzenie kont administratorów.
SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by sending crafted POST requests to an unprotected internal Feign user-creation endpoint exposed via @RestController without authorization checks. Attackers can exploit the gateway's authentication filter, which only validates JWT parsing without verifying user roles or caller identity, and leverage a hardcoded JWT signing key embedded in publicly available JARs to forge tokens and escalate privileges from a low-privilege user to administrator, enabling cross-tenant data pollution and persistent backdoor access.
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.1 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2026-08-28 20:18:30 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-16 13:42:45 UTC |
- https://gist.github.com/sud0why/e73405057dd7414a8c221ef17e0d0059#file-cve-2026-56100-springblade-authbypass-en-md ([email protected])
- https://github.com/chillzhuang/SpringBlade ([email protected])
- https://github.com/chillzhuang/SpringBlade/commit/c69b9547c942c697da2f3ee6a9265b6004abd645 ([email protected])
- https://github.com/chillzhuang/SpringBlade/releases#release-v5.0.0 ([email protected])
- https://www.vulncheck.com/advisories/springblade-privilege-escalation-via-exposed-feign-endpoint ([email protected])