THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-56100 (HIGH 8.1) — SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by sending crafted POST requests to an unprotected internal Feign user-creation endpoint exposed

[NVD] CVE-2026-56100 (HIGH 8.1) — SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by sending crafted POST requests to an unprotected internal Feign user-creation endpoint exposed

mednvdPublished 2026-08-28

CVE-2026-56100 CVSS: 8.1 HIGH Published: 2026-08-28T20:18:30.640

SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by sending crafted POST requests to an unprotected internal Feign user-creation endpoint exposed via @RestController without authorization checks. Atta

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-56100