CVE-2025-70983

I

ncorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to escalate privileges.

Configurations

Configuration 1 (hide)

cpe:2.3:a:bladex:springblade:4.5.0:*:*:*:*:*:*:*

History

11 Feb 2026, 19:28

Type Values Removed Values Added
First Time Bladex springblade
Bladex
CPE cpe:2.3:a:bladex:springblade:4.5.0:*:*:*:*:*:*:*
References () https://gist.github.com/old6ma/9c4d2ba32cd8f562cb80796538157912 - () https://gist.github.com/old6ma/9c4d2ba32cd8f562cb80796538157912 - Third Party Advisory
References () https://github.com/chillzhuang/SpringBlade - () https://github.com/chillzhuang/SpringBlade - Product
References () https://github.com/chillzhuang/SpringBlade/issues/35 - () https://github.com/chillzhuang/SpringBlade/issues/35 - Issue Tracking, Third Party Advisory

23 Jan 2026, 20:15

Type Values Removed Values Added
CWE CWE-862
CWE-284
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.9

23 Jan 2026, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-23 19:15

Updated : 2026-02-11 19:28


NVD link : CVE-2025-70983

Mitre link : CVE-2025-70983

CVE.ORG link : CVE-2025-70983


JSON object : View

Products Affected
CWE
CWE-284

Improper Access Control

CWE-862

Missing Authorization