云虫漏洞库

CVE-2026-72605 - A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary user accounts via the POST /auth/profile/create endpoint. The endpoint is allowlisted from JWT verification, permitting unauthenticated account creation. An attacker can register an account and use it to access protected functionality on the server. - 漏洞详情

漏洞编号:CVE-2026-72605

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-72605

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-306

发布/更新时间:2026-08-11 / 2026-08-28

漏洞描述

A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary user accounts via the POST /auth/profile/create endpoint. The endpoint is allowlisted from JWT verification, permitting unauthenticated account creation. An attacker can register an account and use it to access protected functionality on the server.

相关链接

相关漏洞

« 返回首页