CVE-2026-82594: LogNet grpc-spring-boot-starter Annotation Processing improper authorization
A vulnerability has been found in LogNet grpc-spring-boot-starter up to 5.2.0. Affected is an unknown function of the component Annotation Processing. Such manipulation leads to improper authorization. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
Which deployments should be treated as potentially affected?
Deployments using LogNet grpc-spring-boot-starter version 5.2.0 or earlier should be treated as potentially affected. The available information does not identify configuration conditions or whether a default setup is affected.
What does an attacker need to exploit this issue?
The attack can be performed remotely, but the attacker needs low-level privileges. Exploitation is assessed as high complexity and difficult.
What is the expected security impact if exploitation succeeds?
The reported impact includes low-level effects on confidentiality, integrity, and availability. The issue is characterized as improper authorization in annotation processing, but the affected function and specific authorization bypass scenario are not identified.
Is exploitation already publicly known, and is there a vendor response?
An exploit has been publicly disclosed and may be used. The project was reportedly notified through an issue report but had not responded at the time of the report; no fix or workaround is identified in the available information.