ID:12752 - Exploit for Authentication bypass using an alternate path or channel in Sparx Pro Cloud Server - CVE-2026-42097
Published: May 27, 2026
Sparx Pro Cloud Server
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to bypass authentication.
The vulnerability exists due to improper authentication in the SparxCloudLink.sseap request authentication logic when handling requests without the model query parameter. A remote attacker can omit the model query parameter while supplying the model name in the POST body to bypass authentication.
The issue affects both tls and non-tls ports.