CVE-2026-72605 PUBLISHED

Swing Music Swing Music - Missing Authentication

Assigner: TuranSec
Reserved: 10.08.2026 Published: 11.08.2026 Updated: 11.08.2026

A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary user accounts via the POST /auth/profile/create endpoint. The endpoint is allowlisted from JWT verification, permitting unauthenticated account creation. An attacker can register an account and use it to access protected functionality on the server.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS Score: 7.5

Product Status

Vendor Swing Music
Product Swing Music
Versions
  • affected from 0 to 3.0.0 (incl.)

Credits

  • Xumoyunbek Obidjonov finder

References

Problem Types

  • CWE-306: Missing Authentication for Critical Function CWE