ID:12752 - Exploit for Authentication bypass using an alternate path or channel in Sparx Pro Cloud Server - CVE-2026-42097

 
Main Vulnerability Database Exploits ID:12752 - Exploit for Authentication bypass using an alternate path or channel in Sparx Pro Cloud Server - CVE-2026-42097

ID:12752 - Exploit for Authentication bypass using an alternate path or channel in Sparx Pro Cloud Server - CVE-2026-42097

Published: May 27, 2026


Vulnerability identifier: #VU132370
Vulnerability risk: High
CVE-ID: CVE-2026-42097
CWE-ID: CWE-288
Exploitation vector: Remote access
Vulnerable software:
Sparx Pro Cloud Server

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to bypass authentication.

The vulnerability exists due to improper authentication in the SparxCloudLink.sseap request authentication logic when handling requests without the model query parameter. A remote attacker can omit the model query parameter while supplying the model name in the POST body to bypass authentication.

The issue affects both tls and non-tls ports.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.