Junglewise Threat Intelligence

CVE-2026-56100: SpringBlade privilege escalation via unauthenticated internal endpoint

CVE-2026-56100 · Severity: high · CVSS 8.1 · Published 2026-08-28

Executive brief

SpringBlade is a widely-used open-source Java microservices framework deployed in enterprise backend systems and SaaS platforms. A privilege escalation flaw allows authenticated users to create system administrator accounts by sending forged requests to an internal user-creation endpoint exposed through the API gateway. An attacker with any valid user login can bypass role validation, create backdoor admin accounts with plaintext passwords, and compromise the entire account system and multi-tenant data isolation boundaries.

Technical details

The vulnerability stems from three chained security gaps: (1) the Spring Cloud Gateway discovery locator performs default path rewriting, stripping the service prefix from external requests like POST /blade-system/user/save-user and routing them as /user/save-user to downstream services; (2) the gateway's JWT authentication filter only validates token parsing without verifying user roles or service-to-service caller identity; (3) the UserClient Feign interface is exposed as a @RestController HTTP endpoint with a save-user method that lacks @PreAuth authorization checks and directly persists user objects from the request body without encryption or validation. An authenticated attacker (or one with a forged JWT using a hardcoded or extracted signing key) can craft POST requests to bypass the authorization filter, directly invoke the internal save-user endpoint, and create administrator accounts with arbitrary tenantId, account, password, and roleId fields. Affected versions: 2.7.3 through 4.10.0. Fixed in v5.0.0 by removing the write endpoint and adding InnerFilter to block internal API access.

Affected products

  • SpringBlade SpringBlade 2.7.3 to 4.10.0

Timeline

  • 2026-08-28: disclosed: CVE-2026-56100 published
  • 2026-05-10: patched: Fix released in v5.0.0; v4.10.0 (2026-05-10) is the last affected version

References