An issue was discovered in s-pms SPMS-Server through v1.0. The application contains a hardcoded default access token secret within its core configuration file, which is not overridden or removed in the production environment profile. A remote, unauthenticated attacker can locally forge valid administrative session tokens to completely bypass the authentication mechanism gaining full unauthorized access to protected backend APIs.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-09 21:17
Updated : 2026-09-14 13:18
NVD link : CVE-2026-71801
Mitre link : CVE-2026-71801
CVE.ORG link : CVE-2026-71801
JSON object : View
Products Affected
No product.
CWE
CWE-798
Use of Hard-coded Credentials
