{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/springblade-2.7.3---3.5.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:springblade:springblade:2.7.3:*:*:*:*:*:*:*","cpe:2.3:a:springblade:springblade:3.5.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-56100"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SpringBlade (2.7.3 - 3.5.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","privilege-escalation","authentication-bypass"],"_cs_type":"advisory","_cs_vendors":["SpringBlade"],"content_html":"\u003cp\u003eSpringBlade versions 2.7.3 through 3.5.0 contain a critical privilege escalation vulnerability, tracked as CVE-2026-56100. The vulnerability stems from an improperly secured internal Feign user-creation endpoint exposed via a REST controller that lacks sufficient authorization checks. An attacker with low-privilege authenticated access can leverage a hardcoded JWT signing key, which is embedded within publicly available distributed JAR files, to forge arbitrary administrative tokens. The gateway's authentication filter is insufficient, as it only validates the structural integrity of the JWT without verifying the user's roles, identity, or the caller's origin. By exploiting this flaw, attackers can escalate their access level to system administrator, resulting in full unauthorized access, cross-tenant data pollution, and the establishment of persistent backdoors.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthorized users to elevate their privileges to administrator status. This grants them full control over the SpringBlade environment, leading to the compromise of sensitive cross-tenant data and the installation of persistent administrative backdoors. The vulnerability affects all deployments using SpringBlade versions 2.7.3 through 3.5.0.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification and remediation of SpringBlade instances within the environment.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all SpringBlade instances to a version beyond 3.5.0 that addresses the hardcoded JWT secret and enforces authorization on the Feign user-creation endpoint.\u003c/li\u003e\n\u003cli\u003eAudit access logs for anomalous POST requests directed at internal user-creation endpoints that are exposed via @RestController patterns.\u003c/li\u003e\n\u003cli\u003eRotate the JWT signing keys for all production SpringBlade environments immediately, as the embedded keys in existing versions are considered public knowledge.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T21:37:22Z","date_published":"2026-08-28T21:37:22Z","id":"https://feed.craftedsignal.io/briefs/2026-08-springblade-priv-esc/","summary":"SpringBlade versions 2.7.3 through 3.5.0 allow authenticated attackers to forge administrative tokens using a hardcoded JWT signing key and escalate privileges via an unprotected internal endpoint.","title":"SpringBlade Privilege Escalation via Hardcoded JWT Key and Unprotected Endpoint","url":"https://feed.craftedsignal.io/briefs/2026-08-springblade-priv-esc/"}],"language":"en","title":"CraftedSignal Threat Feed - SpringBlade (2.7.3 - 3.5.0)","version":"https://jsonfeed.org/version/1.1"}