CRITICAL
9.1 CVE-2026-97064 Published 25 Sept 2026
X-SpringBoot Hardcoded Master Login Code Allows Authentication Bypass
Worried this affects your website?
X-SpringBoot through 6.0 contains a hardcoded master login verification code vulnerability.
The default database seed enables a static master code, 172839. An unauthenticated attacker can authenticate as any user by submitting this public code to the emailOrMobileLogin endpoint with a known email or mobile number.
- Affected versions: through 6.0
- Precondition: attacker knows the target user's email or mobile number
- Impact: full account authentication bypass without valid credentials
Reference: CVE-2026-97064 on NVD
← Back to Security News