CRITICAL 9.1 CVE-2026-97064 Published 25 Sept 2026

X-SpringBoot Hardcoded Master Login Code Allows Authentication Bypass

Worried this affects your website?

X-SpringBoot through 6.0 contains a hardcoded master login verification code vulnerability.

The default database seed enables a static master code, 172839. An unauthenticated attacker can authenticate as any user by submitting this public code to the emailOrMobileLogin endpoint with a known email or mobile number.

  • Affected versions: through 6.0
  • Precondition: attacker knows the target user's email or mobile number
  • Impact: full account authentication bypass without valid credentials

Reference: CVE-2026-97064 on NVD

← Back to Security News