Vulnerability
CVE-2026-100192
Descriptive record received from OpenCTI and minimised for consultation in the Intel portal.
- Sharing
- PUBLIC-OSINT
- Confidence
- 100
- Source
- The CVE Program
- Updated
- 26/09/2026 02:36
Description
X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering. Unauthenticated attackers can retrieve these credentials and use them to send arbitrary SMS messages through any tenant's SMS provider, enabling SMS bombing and impersonation attacks.
Aliases and classifications
CWE-306Missing Authentication for Critical Function
Minimised technical details
No raw data- cisa kev
- False
- cvss score
- 6.5
- cvss vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- cvss severity
- MEDIUM
Provenance
Public references
- Vulnerable code
https://github.com/yzcheng90/X-SpringBoot/blob/d74ddba989c0449948ff1ddb0d211b6a7ce81bfa/src/main/java/com/suke/czx/modules/application/controller/XApplicationController.java - product
https://github.com/yzcheng90/X-SpringBoot - Proof of concept
https://github.com/LinYuanyi1/cve-request-poc/blob/master/x-springboot/01_app-credential-sms-abuse.py - VulnCheck Advisory: X-SpringBoot through 6.0 Credential Exposure via Unauthenticated Endpoint
https://www.vulncheck.com/advisories/x-springboot-through-6.0-credential-exposure-via-unauthenticated-endpoint
EudorIA correlation
Intel catalogue
The vulnerability is also available in the EudorIA editorial catalogue.
Open EudorIA analysisPresence in OpenCTI describes an intelligence correlation and does not, by itself, constitute evidence of compromise, legal attribution or operational guidance applicable without context verification.