PatchSiren

s-pms CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL s-pms CVE published 2026-09-09

CVE-2026-71801

A critical vulnerability was discovered in s-pms SPMS-Server through v1.0, where a hardcoded default access token secret is present in the core configuration file. This allows a remote, unauthenticated attacker to forge valid administrative session tokens, bypassing the authentication mechanism and gaining unauthorized access to protected backend APIs.