CVE-2025-70982: Bladex Springblade

Critical severity, CVSS 9.9. EPSS: 0.3% chance of exploitation in the next 30 days.

Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to arbitrarily import sensitive user data.

Affected products

  • Bladex Springblade: version 4.5.0 only

Published 2026-01-26. Last modified 2026-06-17.