CVE-2026-97064 is a critical authentication bypass vulnerability in X-SpringBoot through version 6.0, where a hardcoded static master login verification code '172839' is enabled by default in the database seed. This allows unauthenticated attackers to authenticate as any user by submitting the public master code to the emailOrMobileLogin endpoint with a known email or mobile number.
CVE-2026-97063 is a critical vulnerability in X-SpringBoot through version 6.0. Attackers can request and read login verification codes from unauthenticated endpoints, allowing account hijacking. Defenders should verify exposure and prioritize remediation to prevent account takeover and authentication bypass. The vulnerability affects X-SpringBoot instances, and security teams should assess and remediate [truncated]
CVE-2026-97060 debrief based on the supplied source corpus. X-SpringBoot through 6.0 has a high-severity vulnerability allowing sub-administrators to modify or delete users without proper authorization, potentially leading to privilege escalation and unauthorized access. This vulnerability exists in user management endpoints, specifically via POST /sys/user/update and POST /sys/user/delete endpoints. The [truncated]
CVE-2026-100192 is a medium-severity vulnerability in X-SpringBoot through version 6.0, where the application exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering. This allows unauthenticated attackers to retrieve these credentials and use them to send arbitrary SMS messages through any tenant's SMS provider, enabling SMS bombin [truncated]