CVE-2026-71801

An issue was discovered in s-pms SPMS-Server through v1.0. The application contains a hardcoded default access token secret within its core configuration file, which is not overridden or removed in the production environment profile. A remote, unauthenticated attacker can locally forge valid administrative session tokens to completely bypass the authentication mechanism gaining full unauthorized access to protected backend APIs.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-09 21:17

Updated : 2026-09-14 13:18


NVD link : CVE-2026-71801

Mitre link : CVE-2026-71801

CVE.ORG link : CVE-2026-71801


JSON object : View

Products Affected

No product.

CWE
CWE-798

Use of Hard-coded Credentials