CVE-2026-97368 | chillzhuang SpringBlade up to 5.0.2 user-auth-info Endpoint UserServiceImpl.java UserServiceImpl.userInfo userId authorization
A vulnerability was found in chillzhuang SpringBlade up to 5.0.2. It has been classified as critical. This affects the function UserServiceImpl.userInfo of the file blade-service/blade-system/src/main/java/org/springblade/system/service/impl/UserServiceImpl.java of the component user-auth-info Endpoint. This manipulation of the argument userId causes authorization bypass.
This vulnerability is handled as CVE-2026-97368. The attack can be initiated remotely. Additionally, an exploit exists.
CVE-2026-56100 and CVE-2026-36765 are distinct issues. The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More