CVE-2025-70983: Critical severity Spring SpringBlade vulnerability
Published Jan 23, 2026
·Updated
Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to escalate privileges.
Affected Software
2 affected components
Spring SpringBlade
Bladex Springblade=4.5.0
Event History
Jan 23, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-70983?
CVE-2025-70983 has a high severity rating due to the potential for privilege escalation by low-level users.
2
How do I fix CVE-2025-70983?
To fix CVE-2025-70983, update to the latest version of SpringBlade that addresses the access control issue.
3
What systems are affected by CVE-2025-70983?
CVE-2025-70983 affects SpringBlade v4.5.0 and possibly other versions that utilize the affected authRoutes function.
4
What type of vulnerability is CVE-2025-70983?
CVE-2025-70983 is an access control vulnerability that allows unauthorized privilege escalation.
5
Who is impacted by CVE-2025-70983?
CVE-2025-70983 impacts systems using SpringBlade v4.5.0, especially where low-level privileges are assigned.