← Vulnerability feed

Vulnerability record · CVE-2025-70983 · published 23 January 2026

CVE-2025-70983: Bladex springblade improper access control vulnerability

Bladex · Springblade

Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to escalate privileges.

9.9 CVSS 3.1 Critical EPSS 0.42% · top 66.8% CWE-284 · Improper access controlCWE-862 · Missing authorization
9.9CVSS 3.1 base score
0.42%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to escalate privileges.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-70983 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2025-70982Bladex springblade improper access control vulnerabilityIncorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to arbitrarily import sensitive …EPSS 0.34%9.8CVE-2023-47458Bladex springblade missing authorization vulnerabilityAn issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions control framework.EPSS 0.64%9.8CVE-2023-40787Bladex springblade sql injection vulnerabilityIn SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks, which leads to SQL injection.EPSS 18%9.8CVE-2022-27360Bladex springblade sql injection vulnerabilitySpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment.EPSS 2.0%9.8CVE-2020-16165Bladex springblade sql injection vulnerabilityThe DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause. This is related to the /api/blade-log/api/list as…EPSS 1.2%7.5CVE-2024-33332Bladex springblade sql injection vulnerabilityAn issue discovered in SpringBlade 3.7.1 allows attackers to obtain sensitive information via crafted GET request to api/blade-system/tenant.EPSS 0.68%5.3CVE-2024-8023Bladex springblade sql injection vulnerabilityA vulnerability classified as critical has been found in chillzhuang SpringBlade 4.1.0. Affected is an unknown function of the file /api/blade-system…EPSS 0.64%5.3CVE-2023-40788Bladex springblade exposure of resource to wrong sphere vulnerabilitySpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway resulting in unauthorized access…EPSS 0.77%

Source: NIST National Vulnerability Database (record CVE-2025-70983), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.