CVE-2025-70982: Bladex Springblade
Critical severity, CVSS 9.9. EPSS: 0.3% chance of exploitation in the next 30 days.
Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to arbitrarily import sensitive user data.
Affected products
- Bladex Springblade: version 4.5.0 only
Published 2026-01-26. Last modified 2026-06-17.