CVE-2026-97064: Use of Default Credentials in yzcheng90 X-SpringBoot
X-SpringBoot versions up to and including 6.0 contain a hardcoded static master login verification code (172839) enabled by default in the database seed. This allows unauthenticated attackers to bypass normal authentication by submitting this master code to the emailOrMobileLogin endpoint with a known email or mobile number, effectively authenticating as any user without credentials.
AI Analysis
Technical Summary
CVE-2026-97064 describes a critical vulnerability in the X-SpringBoot product by yzcheng90, affecting all versions up to 6.0 inclusive. The product ships with a hardcoded static master login verification code (172839) embedded in the database seed and enabled by default. Attackers can exploit this by submitting the master code to the emailOrMobileLogin endpoint along with a known email or mobile number, allowing them to authenticate as any user without needing valid credentials. This vulnerability has a CVSS 4.0 score of 9.3, indicating critical severity with network attack vector, no required privileges or user interaction, and high impact on confidentiality and integrity.
Potential Impact
The vulnerability allows complete authentication bypass for any user account if the attacker knows the email or mobile number associated with that account. This can lead to unauthorized access to user data and potentially full account takeover. The critical CVSS score reflects the high risk of exploitation and impact on confidentiality and integrity of the system.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should consider disabling or removing the hardcoded master login verification code if possible, or restrict access to the affected endpoint. Monitor vendor communications for an official patch or update addressing this issue.
CVE-2026-97064: Use of Default Credentials in yzcheng90 X-SpringBoot
Description
X-SpringBoot versions up to and including 6.0 contain a hardcoded static master login verification code (172839) enabled by default in the database seed. This allows unauthenticated attackers to bypass normal authentication by submitting this master code to the emailOrMobileLogin endpoint with a known email or mobile number, effectively authenticating as any user without credentials.
CVSS v4.0
Score 9.3critical
Affected software
yzcheng90
X-SpringBoot
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-97064 describes a critical vulnerability in the X-SpringBoot product by yzcheng90, affecting all versions up to 6.0 inclusive. The product ships with a hardcoded static master login verification code (172839) embedded in the database seed and enabled by default. Attackers can exploit this by submitting the master code to the emailOrMobileLogin endpoint along with a known email or mobile number, allowing them to authenticate as any user without needing valid credentials. This vulnerability has a CVSS 4.0 score of 9.3, indicating critical severity with network attack vector, no required privileges or user interaction, and high impact on confidentiality and integrity.
Potential Impact
The vulnerability allows complete authentication bypass for any user account if the attacker knows the email or mobile number associated with that account. This can lead to unauthorized access to user data and potentially full account takeover. The critical CVSS score reflects the high risk of exploitation and impact on confidentiality and integrity of the system.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should consider disabling or removing the hardcoded master login verification code if possible, or restrict access to the affected endpoint. Monitor vendor communications for an official patch or update addressing this issue.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-23T23:51:32.671Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab6beaaf7a7c5410621ae4f
Added to database: 09/25/2026, 18:34:18 UTC
Last enriched: 09/25/2026, 18:47:40 UTC
Last updated: 09/25/2026, 19:46:49 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.