CRITICAL
9.1 CVE-2026-97063 Published 25 Sept 2026
X-SpringBoot Login Verification Code Disclosure Vulnerability
Worried this affects your website?
X-SpringBoot through 6.0 has a login verification code disclosure vulnerability.
The software returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners.
Attackers can request codes using known mobile numbers or email addresses, read them from responses, and authenticate as victims via POST /sys/emailOrMobileLogin/login to hijack accounts.
Reference: CVE-2026-97063 on NVD
← Back to Security News