PatchSiren cyber security CVE debrief
CVE-2026-97060 yzcheng90 CVE debrief
CVE-2026-97060 debrief based on the supplied source corpus. X-SpringBoot through 6.0 has a high-severity vulnerability allowing sub-administrators to modify or delete users without proper authorization, potentially leading to privilege escalation and unauthorized access. This vulnerability exists in user management endpoints, specifically via POST /sys/user/update and POST /sys/user/delete endpoints. The CVE record and NVD entry provide details on the vulnerability, including its description and CVSS score of 8.6. However, the corpus lacks specific information on affected versions, exploitation, and remediation. Defenders and administrators should assess exposure and prioritize to
- Vendor
- yzcheng90
- Product
- X-SpringBoot
- CVSS
- HIGH 8.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-25
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-09-25
- Advisory updated
- 2026-09-25
Who should care
Defenders and administrators of X-SpringBoot through 6.0 systems, particularly those with user management functionality, should assess exposure and prioritize mitigation. This includes reviewing and updating user management permissions to prevent unauthorized actions, verifying and restricting access to user management endpoints, and ensuring proper authorization mechanisms are in place. Additionally, security teams and vulnerability management teams need
Why it matters
CVE-2026-97060 is a high-severity vulnerability in X-SpringBoot through 6.0 that allows sub-administrators to modify or delete users without proper authorization, potentially leading to privilege escalation and unauthorized access.
- Potential unauthorized modification or deletion of user accounts
- Possible escalation of privileges for sub-administrators
- Risk of unauthorized password resets for any account, including the super administrator
- Need for verification of user management permissions and authorization mechanisms
Technical summary
X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification via POST /sys/user/update and POST /sys/user/delete endpoints. This vulnerability, with a CVSS score of 8.6, enables attackers with user-management permissions to reset passwords for any account, rebind roles, or delete users. The lack of proper authorization mechanisms in user management endpoints poses a significant risk, as it could lead to unauthorized access and privilege escalation. To mitigate this vulnerability, it is essential to verify and restrict access to these endpoints, ensure proper authorization mechanisms are in place, and
Defensive priority
Defenders should prioritize verifying and mitigating the vulnerability in X-SpringBoot through 6.0, focusing on restricting access to user management endpoints and ensuring proper authorization mechanisms are in place.
Recommended defensive actions
- Verify and restrict access to user management endpoints in X-SpringBoot through 6.0
- Ensure proper authorization mechanisms are in place for user management
- Review and update user management permissions to prevent unauthorized actions
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD entry provide details on the vulnerability in X-SpringBoot through 6.0, including its description and CVSS score. However, the corpus lacks specific information on affected versions, exploitation, and remediation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-97060 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-97060
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-97060 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97060
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/LinYuanyi1/cve-request-poc/blob/master/x-springboot/03_user-admin-cross-object-bola.py
-
Source reference
Unverified legacy reference
URL: https://github.com/yzcheng90/X-SpringBoot
-
Source reference
Unverified legacy reference
URL: https://github.com/yzcheng90/X-SpringBoot/blob/d74ddba989c0449948ff1ddb0d211b6a7ce81bfa/src/main/java/com/suke/czx/modules/sys/controller/SysUserController.java
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/x-springboot-through-6.0-authorization-bypass-via-user-management
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.