Impact
The vulnerability is an authentication bypass that allows remote attackers to create user accounts without prior authentication using the POST /auth/profile/create endpoint. Because this endpoint is explicitly excluded from JWT verification, any client can post user data and receive a valid account. Once created, the account can be used to access protected server features, effectively granting the attacker the same privileges as a legitimate user.
Affected Systems
Swing Music 3.0.0 from the vendor Swing Music. No other versions are explicitly listed as affected.
Risk and Exploitability
The CVSS score of 7.5 reflects a high severity exploited remotely. Although no EPSS data is available, the lack of authentication and straightforward endpoint invocation make exploitation accessible. The issue is not currently listed in the CISA KEV catalog, but the ability to create arbitrary accounts on an exposed web service presents significant risk for unauthorized access to protected functionality and potential further malicious activity.
OpenCVE Enrichment