Impact
An attacker can bypass authentication by forging administrative session tokens because the application stores a hardcoded default access token secret in its core configuration and never replaces it when running in the production profile. The vulnerability allows the attacker to generate a valid token without any credentials, giving unrestricted access to the protected backend APIs.
Affected Systems
Affected systems are installations of the s‑pms SPMS‑Server application up to and including version 1.0. No vendor or product names beyond the application identifier are listed, so any environment running this version with the default configuration is potentially impacted.
Risk and Exploitability
Because the exploit requires only the knowledge of the hardcoded secret, it can be carried out remotely and without user interaction, making it both high‑impact and high‑availability. While no public EPSS score is available and the issue is not listed in the CISA KEV catalog, the severity is high due to unauthenticated remote authentication bypass. The attacker can freely perform any operation that an administrator can, potentially leading to data exfiltration, configuration changes, or system takeover.
OpenCVE Enrichment