No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 24 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in chillzhuang SpringBlade up to 5.0.2. This affects the function UserServiceImpl.userInfo of the file blade-service/blade-system/src/main/java/org/springblade/system/service/impl/UserServiceImpl.java of the component user-auth-info Endpoint. This manipulation of the argument userId causes authorization bypass. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. CVE-2026-56100 and CVE-2026-36765 are distinct issues. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | chillzhuang SpringBlade user-auth-info Endpoint UserServiceImpl.java UserServiceImpl.userInfo authorization | |
| First Time appeared |
Chillzhuang
Chillzhuang springblade |
|
| Weaknesses | CWE-285 CWE-639 |
|
| CPEs | cpe:2.3:a:chillzhuang:springblade:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Chillzhuang
Chillzhuang springblade |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-24T20:30:09.621Z
Reserved: 2026-09-24T13:58:06.456Z
Link: CVE-2026-97368
No data.
Status : Deferred
Published: 2026-09-24T21:18:58.953
Modified: 2026-09-24T21:18:59.100
Link: CVE-2026-97368
No data.
OpenCVE Enrichment
No data.