CRITICAL
s-pms
CVE published 2026-09-09
CVE-2026-71801
A critical vulnerability was discovered in s-pms SPMS-Server through v1.0, where a hardcoded default access token secret is present in the core configuration file. This allows a remote, unauthenticated attacker to forge valid administrative session tokens, bypassing the authentication mechanism and gaining unauthorized access to protected backend APIs.