Access Control Flaw in SpringBlade Affects Sensitive User Data Import
CVE-2025-70982

9.9CRITICAL

Key Information:

Vendor
CVE Published:
26 January 2026

What is CVE-2025-70982?

An access control vulnerability in the importUser function of SpringBlade v4.5.0 allows users with minimal privileges to import sensitive user data. This flaw could enable unauthorized access to confidential information, potentially leading to data breaches. Organizations using this version need to implement immediate measures to secure their systems and prevent exploitation.

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.