Description
A vulnerability has been found in LogNet grpc-spring-boot-starter up to 5.2.0. Affected is an unknown function of the component Annotation Processing. Such manipulation leads to improper authorization. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-08-30
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Improper authorization
Action: Assess Impact
AI Analysis

Impact

A flaw in Annotation Processing within LogNet grpc‑spring‑boot‑starter allows an attacker to manipulate the component in a way that bypasses the application’s established authorization controls. This weakness corresponds to CWE‑266 and CWE‑285. The public disclosure and remote exploitation potential mean that, if a suitable vector is identified, an adversary could gain unauthorized access to privileged functions or data. The vulnerability requires a high complexity level and is considered difficult to exploit, but the fact that it has already been disclosed publicly raises the risk of future exploitation attempts once a viable attack path is discovered.

Affected Systems

LogNet grpc‑spring‑boot‑starter versions up to 5.2.0 are affected. This conclusion is drawn from the vendor’s release notes and issue tracker; no other LogNet components have been identified as vulnerable by the vendor, based on the information supplied by the CNA and the absence of additional affected products listed in the CNA data.

Risk and Exploitability

With a CVSS score of 2.3, the overall severity is low. The EPSS score is not available, inferred from the lack of a published EPSS value in the assessment data. The vulnerability is not listed in CISA’s KEV catalog, an inference from the KEV field value. The attack requires remote access and high complexity, making it difficult for attackers to weaponize; however, its public disclosure raises the possibility that malicious actors may attempt to exploit it once a suitable vector is discovered.

Generated by OpenCVE AI on August 31, 2026 at 01:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for an official patch or upgraded release of LogNet grpc‑spring‑boot‑starter that addresses the Annotation Processing authorization flaw.
  • If no patch is available, block external traffic to the Annotation Processing endpoint or service, limiting access to trusted internal networks only.
  • Implement application‑level access controls, ensuring that only authorized users can invoke the Annotation Processing functionality, and add logging to detect abuse.
  • Continuously monitor security advisories and apply any subsequent patches or workarounds promptly.

Generated by OpenCVE AI on August 31, 2026 at 01:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 30 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in LogNet grpc-spring-boot-starter up to 5.2.0. Affected is an unknown function of the component Annotation Processing. Such manipulation leads to improper authorization. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title LogNet grpc-spring-boot-starter Annotation Processing improper authorization
First Time appeared Lognet
Lognet grpc-spring-boot-starter
Weaknesses CWE-266
CWE-285
CPEs cpe:2.3:a:lognet:grpc-spring-boot-starter:*:*:*:*:*:*:*:*
Vendors & Products Lognet
Lognet grpc-spring-boot-starter
References
Metrics cvssV2_0

{'score': 4.6, 'vector': 'AV:N/AC:H/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Lognet Grpc-spring-boot-starter
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-31T16:14:49.507Z

Reserved: 2026-08-30T06:19:31.700Z

Link: CVE-2026-82594

cve-icon Vulnrichment

Updated: 2026-08-31T16:14:43.875Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T00:16:41.800

Modified: 2026-08-31T20:56:08.800

Link: CVE-2026-82594

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T11:19:00Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-285

    Improper Authorization