Junglewise Threat Intelligence

CVE-2026-79571: springboot-project authentication bypass in seller authorization

CVE-2026-79571 · Severity: critical · CVSS 9.1 · Published 2026-09-08

Executive brief

springboot-project is an open-source WeChat ordering and dining system. Due to an authentication check being completely commented out in the seller authorization component, any unauthenticated attacker can access all seller management interfaces to view and modify products, orders, and categories without logging in. This allows complete unauthorized control over the seller's inventory and order operations.

Technical details

The SellerAuthorizeAspect component, which implements authorization for all seller management endpoints under /seller/product/**, /seller/order/**, and /seller/category/**, has its entire AOP pointcut definition and authorization verification method (@Before doVerify) commented out. The project lacks any alternative interceptor or filter to enforce authentication. As a result, these endpoints are completely unauthenticated and accessible over the network without any credentials. An attacker can perform read operations (list products, orders) and write operations (modify product status, cancel orders, update categories) directly via HTTP requests without login. The vulnerability has been verified in practice with successful database modifications.

Affected products

  • SqMax springboot-project v1.0.0

Timeline

  • 2026-09-08: disclosed

References