CVE-2026-72605

Source
https://cve.org/CVERecord?id=CVE-2026-72605
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72605.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72605
Published
2026-08-11T11:15:37Z
Modified
2026-08-30T03:30:24Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
Swing Music Swing Music - Missing Authentication
Details

A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary user accounts via the POST /auth/profile/create endpoint. The endpoint is allowlisted from JWT verification, permitting unauthenticated account creation. An attacker can register an account and use it to access protected functionality on the server.

Database specific
{
    "cna_assigner": "TuranSec",
    "cwe_ids": [
        "CWE-306"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72605.json"
}
References

Affected packages

Git / github.com/swingmx/swingmusic

Affected ranges

Type
GIT
Repo
https://github.com/swingmx/swingmusic
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.0.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

Other
linux-beta
v1
v1.*
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.6
v1.4.7
v1.4.8
v2.*
v2.0.0
v2.0.0.beta10
v2.0.0.beta11
v2.0.0.beta12
v2.0.0.beta13
v2.0.1
v2.0.2
v2.0.3
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.0.9
v2.1.0
v2.1.1
v2.1.10
v2.1.2
v2.1.3
v2.1.4
v3.*
v3.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72605.json"