CVE-2026-105610
Deferred Deferred - Pending Action

Improper Authorization in SpringBlade Parameter Submit

Vulnerability report for CVE-2026-105610, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: VulDB

Description

A vulnerability was found in chillzhuang SpringBlade up to 5.0.1. The impacted element is an unknown function of the file blade-service/blade-system/src/main/java/org/springblade/system/controller/ParamController.java of the component Parameter Submit Management. The manipulation of the argument initPassword results in improper authorization. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
chillzhuang SpringBlade 5.0.0
chillzhuang SpringBlade 5.0.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-266 A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in SpringBlade versions up to 5.0.1. It involves improper authorization in the Parameter Submit Management component. Specifically, the endpoint `/param/submit` allows tenant administrators to modify platform-global settings without proper validation. The `initPassword` parameter can be manipulated, enabling unauthorized changes to global configuration values like account initialization passwords.

Detection Guidance

Check for unauthorized modifications to the global parameter 'account.initPassword' via the /param/submit endpoint. Monitor logs for requests to this endpoint with tenant admin privileges but without platform admin checks. Verify if the blade_param table contains unexpected changes outside tenant-scoped records.

Impact Analysis

An attacker with tenant admin rights could alter global parameters affecting the entire platform. This may disrupt services relying on shared configurations. While direct cross-tenant account takeover wasn't observed, unauthorized modifications could lead to system instability or unexpected behavior in dependent components.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized modification of global configuration settings, such as password initialization parameters, by tenant administrators. Improper authorization may lead to unauthorized access or data exposure, which are key concerns under these regulations.

Mitigation Strategies

Restrict access to the /param/submit endpoint to only platform administrators by enforcing HAS_ROLE_ADMINISTRATOR checks. Audit the blade_param table for unauthorized changes and revert any suspicious modifications. Consider implementing tenant scoping for global parameters to prevent cross-tenant modifications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105610. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart