{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/x-springboot/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:x-springboot:x-springboot:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-97063"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["X-SpringBoot (\u003c= 6.0)"],"_cs_severities":["critical"],"_cs_tags":["web-application","authentication-bypass","cve","webserver","vulnerability","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":["X-SpringBoot"],"content_html":"\u003cp\u003eX-SpringBoot versions 6.0 and earlier contain a critical vulnerability where sensitive login verification codes are returned directly in the HTTP response body for unauthenticated API endpoints. Specifically, the endpoints '/sys/mobile/code' and '/sys/email/code' leak these codes without requiring authentication and without sending the codes to the intended account owners. An attacker can supply a target's mobile number or email address as a parameter to these endpoints and receive the valid verification code in the server response. With this code, the attacker can then authenticate as the victim via the '/sys/emailOrMobileLogin/login' endpoint. This flaw enables widespread account hijacking by bypassing standard MFA or verification workflows. Defenders should identify instances of X-SpringBoot 6.0 or lower and restrict access to these endpoints or upgrade to a patched version once available.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target mobile number or email address.\u003c/li\u003e\n\u003cli\u003eAttacker sends an unauthenticated HTTP GET request to /sys/mobile/code or /sys/email/code.\u003c/li\u003e\n\u003cli\u003eThe vulnerable application processes the request and generates a verification code.\u003c/li\u003e\n\u003cli\u003eThe application improperly embeds the code in the JSON response body sent to the client.\u003c/li\u003e\n\u003cli\u003eThe attacker parses the HTTP response to extract the verification code.\u003c/li\u003e\n\u003cli\u003eThe attacker submits the stolen code along with the target's identifier to /sys/emailOrMobileLogin/login.\u003c/li\u003e\n\u003cli\u003eThe application validates the code, granting the attacker a session as the target user.\u003c/li\u003e\n\u003cli\u003eAttacker gains full unauthorized access to the victim's account.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to hijack any account within an exposed X-SpringBoot instance. This could lead to full account takeover, unauthorized access to sensitive user data, and potential lateral movement if the hijacked accounts possess elevated privileges. Given the CVSS score of 9.1, the impact is severe, particularly for internet-facing installations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eIdentify and inventory all internet-facing instances of X-SpringBoot running version 6.0 or lower.\u003c/li\u003e\n\u003cli\u003eImplement strict network-level access control to block external access to the /sys/mobile/code and /sys/email/code endpoints until a patch is applied.\u003c/li\u003e\n\u003cli\u003eDeploy web application firewall (WAF) rules to inspect and alert on suspicious patterns of repeated requests to verification endpoints originating from single source IPs.\u003c/li\u003e\n\u003cli\u003eMonitor application logs for high volumes of 200 OK responses to /sys/mobile/code or /sys/email/code that are not followed by successful logins from the target user's known devices.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-25T20:55:27Z","date_published":"2026-09-25T20:55:09Z","id":"https://feed.craftedsignal.io/briefs/2026-09-x-springboot-auth-bypass/","summary":"The X-SpringBoot application up to version 6.0 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve login verification codes and hijack user accounts.","title":"Information Disclosure and Account Hijacking in X-SpringBoot","url":"https://feed.craftedsignal.io/briefs/2026-09-x-springboot-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - X-SpringBoot","version":"https://jsonfeed.org/version/1.1"}