PT-2026-4774 · Unknown · Springblade

Published

2026-01-26

·

Updated

2026-01-31

·

CVE-2025-70982

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SpringBlade version 4.5.0
Description A flaw exists in the importUser function that allows attackers with limited privileges to import sensitive user data without proper authorization. The issue is due to incorrect access control.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the importUser function until a patch is available.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-70982

Affected Products

Springblade