CVE-2026-97368: Authorization Bypass in chillzhuang SpringBlade
A weakness has been identified in chillzhuang SpringBlade up to 5.0.2. This affects the function UserServiceImpl.userInfo of the file blade-service/blade-system/src/main/java/org/springblade/system/service/impl/UserServiceImpl.java of the component user-auth-info Endpoint. This manipulation of the argument userId causes authorization bypass. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. CVE-2026-56100 and CVE-2026-36765 are distinct issues. The vendor was contacted early about this disclosure but did not respond in any way.
AI Analysis
Technical Summary
This vulnerability in chillzhuang SpringBlade up to version 5.0.2 involves an authorization bypass caused by improper handling of the userId argument in the UserServiceImpl.userInfo function. An attacker can remotely manipulate this argument to gain unauthorized access to user information or functionality that should be restricted. The issue is distinct from other CVEs affecting the product and has been publicly disclosed without vendor remediation or patch availability.
Potential Impact
Successful exploitation allows remote attackers to bypass authorization checks in the user-auth-info endpoint, potentially accessing or manipulating user information without proper permissions. This could lead to unauthorized data exposure or actions within the affected system. The impact is rated medium based on the CVSS score and vector, indicating limited but significant risk.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vendor has not responded or provided a fix, users should monitor official channels for updates. Until a patch is available, consider restricting access to the affected endpoint or implementing additional access controls to mitigate unauthorized access risks.
CVE-2026-97368: Authorization Bypass in chillzhuang SpringBlade
Description
A weakness has been identified in chillzhuang SpringBlade up to 5.0.2. This affects the function UserServiceImpl.userInfo of the file blade-service/blade-system/src/main/java/org/springblade/system/service/impl/UserServiceImpl.java of the component user-auth-info Endpoint. This manipulation of the argument userId causes authorization bypass. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. CVE-2026-56100 and CVE-2026-36765 are distinct issues. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS v4.0
Score 5.3medium
Affected software
chillzhuang
SpringBlade
pkg:maven/chillzhuang/springbladecpe:2.3:a:chillzhuang:springblade:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in chillzhuang SpringBlade up to version 5.0.2 involves an authorization bypass caused by improper handling of the userId argument in the UserServiceImpl.userInfo function. An attacker can remotely manipulate this argument to gain unauthorized access to user information or functionality that should be restricted. The issue is distinct from other CVEs affecting the product and has been publicly disclosed without vendor remediation or patch availability.
Potential Impact
Successful exploitation allows remote attackers to bypass authorization checks in the user-auth-info endpoint, potentially accessing or manipulating user information without proper permissions. This could lead to unauthorized data exposure or actions within the affected system. The impact is rated medium based on the CVSS score and vector, indicating limited but significant risk.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vendor has not responded or provided a fix, users should monitor official channels for updates. Until a patch is available, consider restricting access to the affected endpoint or implementing additional access controls to mitigate unauthorized access risks.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-09-24T13:58:06.456Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab59083f7a7c54106d840f0
Added to database: 09/24/2026, 21:05:07 UTC
Last enriched: 09/24/2026, 21:17:50 UTC
Last updated: 09/25/2026, 01:59:16 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.