HIGH
Swing Music
CVE published 2026-08-11
CVE-2026-72605
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T12:17:43.623Z and has not been modified since then. This CVE-2026-72605 involves a missing authentication vulnerability in Swing Music 3.0.0, which allows unauthenticated remote attackers to create arbitrary user accounts via the POST /auth/profile/create endpoint. The endpoint is allowlisted fro [truncated]