Junglewise Threat Intelligence

CVE-2026-6886: BorG Technology Corporation Borg SPM 2007 authentication bypass

CVE-2026-6886 · Severity: critical · CVSS 9.8 · Published 2026-04-23

Technologies: BorG Technology Corporation SPM 2007. Vendors: BorG Technology Corporation.

Executive brief

BorG SPM 2007, a legacy software product used for business process management, contains a critical security flaw. This vulnerability allows an unauthorized person to bypass security checks and log into the system as any user, including administrators. An attacker could gain full access to sensitive corporate data and system functions without needing a password.

Technical details

Borg SPM 2007 (legacy version) is vulnerable to an authentication bypass (CWE-1390). The flaw allows a remote, unauthenticated attacker to circumvent identity verification mechanisms and gain access to the application with the privileges of any existing user account. The vulnerability is exploited over the network without requiring user interaction. While the specific vulnerable component within the 2007 version is not detailed, the vendor recommends upgrading to SPM2025 SP1 or contacting them for patching assistance if under a maintenance contract.

Affected products

  • BorG Technology Corporation Borg SPM 2007 2007 (Sales ended in 2008)

Timeline

  • 2026-04-23: disclosed
  • 2026-04-23: advisory

References

Related threats