CVE-2026-72605: Swing Music

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary user accounts via the POST /auth/profile/create endpoint. The endpoint is allowlisted from JWT verification, permitting unauthenticated account creation. An attacker can register an account and use it to access protected functionality on the server.

Affected products

Published 2026-08-11. Last modified 2026-08-28.