High severity7.5NVD Advisory· Published Aug 11, 2026· Updated Aug 11, 2026
CVE-2026-72605
CVE-2026-72605
Description
A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary user accounts via the POST /auth/profile/create endpoint. The endpoint is allowlisted from JWT verification, permitting unauthenticated account creation. An attacker can register an account and use it to access protected functionality on the server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <3.0.0
Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.