SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-71801

CRITICAL · CVSS 9.8 EPSS 0.53% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The s-pms SPMS-Server application contains a hardcoded default access token secret in its core configuration file, which remains unchanged in production environments. This vulnerability allows remote, unauthenticated attackers to forge valid administrative session tokens, enabling them to bypass authentication and gain full unauthorized access to protected backend APIs. Organizations using this application should prioritize remediation to prevent potential exploitation and unauthorized access to sensitive data.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-71801
Severity
CRITICAL
CVSS
9.8
EPSS
0.53%

Original NVD Description

An issue was discovered in s-pms SPMS-Server through v1.0. The application contains a hardcoded default access token secret within its core configuration file, which is not overridden or removed in the production environment profile. A remote, unauthenticated attacker can locally forge valid administrative session tokens to completely bypass the authentication mechanism gaining full unauthorized access to protected backend APIs.