CVE-2026-71801: S-pms SPMS-Server vulnerability
An issue was discovered in s-pms SPMS-Server through v1.0. The application contains a hardcoded default access token secret within its core configuration file, which is not overridden or removed in the production environment profile. A remote, unauthenticated attacker can locally forge valid administrative session tokens to completely bypass the authentication mechanism gaining full unauthorized access to protected backend APIs.
Affected Software
Event History
Frequently Asked Questions
Which deployments should be treated as exposed?
s-pms SPMS-Server deployments through version 1.0 should be treated as affected because the default token secret remains present in the production environment profile.
Does exploitation require an existing account or valid credentials?
No. A remote unauthenticated attacker can forge valid administrative session tokens using the hardcoded secret and bypass authentication.
What level of access can a successful attacker obtain?
A successful attacker can gain full unauthorized access to protected backend APIs with administrative session tokens.