CVE-2026-72605
A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary user accounts via th
CVSS
7.5
Alto
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 11 ago 2026 · Última mod.: 11 ago 2026 · CWE-306
Sin historial EPSS suficiente todavía.
A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary user accounts via the POST /auth/profile/create endpoint. The endpoint is allowlisted from JWT verification, permitting unauthenticated account creation. An attacker can register an account and use it to access protected functionality on the server.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-649218.8 ALT—
———Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.5hCVE-2026-627777.8 ALT—
———Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.5hCVE-2026-613677.8 ALT—
———Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.6hCVE-2026-613657.8 ALT—
———Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.6hCVE-2026-613647.8 ALT—
———Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.6hCVE-2026-613567.8 ALT—
———Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.6h