← Back to search

CVE-2026-97063

9.1 CRITICALpublic exploit available

Published 2026-09-25 · Updated 2026-09-28

AI risk analysis

Summary
The flaw allows attackers to request login verification codes from unauthenticated endpoints, which can be read from HTTP responses and used to hijack user accounts.
Exploitability
Exploitation is relatively easy as attackers can request codes using known mobile numbers or email addresses without authentication.
Blast radius
If exploited, attackers can hijack user accounts, potentially leading to unauthorized access and data breaches.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to X-SpringBoot 6.0 or later.
auth-bypassweblogincode-exposure

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners. Attackers can request codes using known mobile numbers or email addresses, read them from responses, and authenticate as victims via POST /sys/emailOrMobileLogin/login to hijack accounts.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-287

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.