CRITICAL 9.1 CVE-2026-97063 Published 25 Sept 2026

X-SpringBoot Login Verification Code Disclosure Vulnerability

Worried this affects your website?

X-SpringBoot through 6.0 has a login verification code disclosure vulnerability.

The software returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners.

Attackers can request codes using known mobile numbers or email addresses, read them from responses, and authenticate as victims via POST /sys/emailOrMobileLogin/login to hijack accounts.

Reference: CVE-2026-97063 on NVD

← Back to Security News