CVE-2026-79571
Deferred Deferred - Pending Action

Incorrect Access Control in Springboot-Project v1.0.0

Vulnerability report for CVE-2026-79571, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-09

Assigner: MITRE

Description

Incorrect access control in the SellerAuthorizeAspect component of springboot-project v1.0.0 allows unauthenticated attackers to access all seller management interfaces and list all products/orders, put products on/off sale, finish/cancel orders, and modify categories without authentication.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
springboot-project springboot-project 1.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an authentication bypass vulnerability in springboot-project v1.0.0 where the SellerAuthorizeAspect component has its authorization checks disabled. This allows unauthenticated users to access seller management interfaces and perform actions like listing products, managing orders, and modifying categories without any credentials.

Detection Guidance

Check if the vulnerable endpoints (/seller/product/**, /seller/order/**, /seller/category/**) are exposed by sending HTTP requests to these paths without authentication. Use tools like curl to test access: curl -v http://<target>/seller/product/list or curl -v http://<target>/seller/order/list. If responses contain sensitive data without requiring credentials, the system is likely vulnerable.

Impact Analysis

An attacker could exploit this to gain unauthorized access to sensitive seller functions, such as listing all products and orders, changing product availability, altering order statuses, or modifying categories. This could lead to data breaches, financial loss, or disruption of services if the system is exposed to the internet.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA by allowing unauthorized access to sensitive data such as product listings, orders, and categories. GDPR requires protection of personal data, while HIPAA mandates secure handling of health-related information. A breach could result in legal penalties and reputational damage.

Mitigation Strategies

Immediately update the springboot-project Seller-Side to a patched version if available. If not, remove or restrict access to the vulnerable endpoints (/seller/product/**, /seller/order/**, /seller/category/**) via firewall rules or web server configurations. Implement strict authentication checks for all seller management interfaces.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79571. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart