Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-56100
SpringBlade 2.7.3 < 5.0.0 Privilege Escalation via Exposed Feign Endpoint
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N H H N 8.6 .0053 42.5 —
AFFECTED
Product Versions Fixed
SpringBlade 2.7.3 – —
TIMELINE
Jun 18 Reserved by VulnCheck
Aug 28 Published (CNA: VulnCheck)
Aug 29 EXPLOIT PUBLISHED — CVE-2026-56100 (SpringBlade). Public exploit reference added.
Sep 24 EXPLOIT PUBLISHED — CVE-2026-56100 (SpringBlade). Public exploit reference added.
Description
SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by sending crafted POST requests to an unprotected internal Feign user-creation endpoint exposed via @RestController without authorization checks. Attackers can exploit the gateway's authentication filter, which only validates JWT parsing without verifying user roles or caller identity, and leverage a hardcoded JWT signing key embedded in publicly available JARs to forge tokens and escalate privileges from a low-privilege user to administrator, enabling cross-tenant data pollution and persistent backdoor access.
Lifecycle
Complete event history — 4 events, chronological
| Date | Event | Detail |
| June 18, 2026 | Reserved | Reserved by VulnCheck |
| August 28, 2026 | Published | Published (CNA: VulnCheck) |
| August 29, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-56100 (SpringBlade). Public exploit reference added. |
| September 24, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-56100 (SpringBlade). Public exploit reference added. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| SpringBlade | SpringBlade | — | 2.7.3 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-56100 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.