CVE-2026-71801: S-pms SPMS-Server vulnerability

Published Sep 9, 2026
·
Updated

An issue was discovered in s-pms SPMS-Server through v1.0. The application contains a hardcoded default access token secret within its core configuration file, which is not overridden or removed in the production environment profile. A remote, unauthenticated attacker can locally forge valid administrative session tokens to completely bypass the authentication mechanism gaining full unauthorized access to protected backend APIs.

Affected Software

1 affected component
s-pms SPMS-Server>through v1.0<=v1.0

Event History

Sep 9, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description

Frequently Asked Questions

1

Which deployments should be treated as exposed?

s-pms SPMS-Server deployments through version 1.0 should be treated as affected because the default token secret remains present in the production environment profile.

2

Does exploitation require an existing account or valid credentials?

No. A remote unauthenticated attacker can forge valid administrative session tokens using the hardcoded secret and bypass authentication.

3

What level of access can a successful attacker obtain?

A successful attacker can gain full unauthorized access to protected backend APIs with administrative session tokens.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203