Back

CRITICAL

X-SpringBoot through 6.0 Authentication Bypass via Login Code

Published Sep 25, 2026

Description

X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners. Attackers can request codes using known mobile numbers or email addresses, read them from responses, and authenticate as victims via POST /sys/emailOrMobileLogin/login to hijack accounts.

Affected products

Remediation

No remediation recorded yet.

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Sep 25, 2026
Updated Sep 25, 2026
Reserved Sep 23, 2026
CISA Vulnrichment
Updated Sep 25, 2026
NVD
Status Received
Modified Sep 25, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulnCheck
Published Sep 25, 2026
Updated Sep 25, 2026
Exploited since n/a
EUVD-2026-87255