Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-97064: X-SpringBoot allows anyone to log in with master code

CVE-2026-97064 · published 2 days ago
Summary

X‑SpringBoot versions up to 6.0 include a default master login code (172839) that is built into the initial database. Because this code is enabled by default, anyone who knows it can sign in as any user simply by providing a known email or phone number. Update the software to a version that removes the hard‑coded code or reconfigure the system to delete or change the master code and reset user passwords.

Original advisory text
X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as any user by submi...
X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as any user by submitting the public master code to the emailOrMobileLogin endpoint with a known email or mobile number.
Severity
9.3 Critical
CVSS 3.1: 9.1 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-1392Use of Default Credentials
Timeline
Published25 Sep 2026
Updated27 Sep 2026
First seen25 Sep 2026
Sources
Track software like this
Free during beta