#xspringboot
CVE-2026-97063 - x-springboot
The X‑SpringBoot framework (up to version 6.0) returns login codes to anyone who asks for them, even if they are not the account owner. An attacker can request a code for…

Too many irrelevant or confusing CVEs? Use stackflag.com

#xspringboot #yzcheng90 #CVE #infosec
CVE-2026-97063: X-SpringBoot through 6.0 Authentication Bypass via Login Code
X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code.
stackflag.com
September 26, 2026 at 3:00 PM