LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-31271

CVE-2026-31271 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: April 9, 2026

megagao production_ssm - Authorization Bypass

Published: April 7, 2026Updated: April 9, 2026Remote Exploitable

Overview

megagao production_ssm v1.0 contains an authorization bypass caused by missing authentication checks in UserController.java insert() method, letting unauthenticated attackers create super administrator accounts, exploit requires no authentication.

Severity & Score

Severity: Critical
CVSS Score: 9.8

Impact

Unauthenticated attackers can create super administrator accounts, leading to complete system compromise.

Mitigation

Update to the latest version with proper authentication checks on user addition functionality.

Details

CVE ID
CVE-2026-31271
Severity
Critical
CVSS Score
9.8
Type
broken_access_control
Status
unconfirmed

CWE

  • CWE-288

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H