CVE-2026-72605
A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary user accounts via th
CVSS
7.5
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 11, 2026 · Last modified: Aug 11, 2026 · CWE-306
Not enough EPSS history yet.
A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary user accounts via the POST /auth/profile/create endpoint. The endpoint is allowlisted from JWT verification, permitting unauthenticated account creation. An attacker can register an account and use it to access protected functionality on the server.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-649218.8 HIG—
———Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.5hCVE-2026-627777.8 HIG—
———Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.5hCVE-2026-613677.8 HIG—
———Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.5hCVE-2026-613657.8 HIG—
———Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.5hCVE-2026-613647.8 HIG—
———Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.5hCVE-2026-613567.8 HIG—
———Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.5h