CVE-2026-97064Critical· 9.1▾ MidnightX-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as any user by submitting the public master code to the emai…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as any user by submitting the public master code to the emailOrMobileLogin endpoint with a known email or mobile number.
X-SpringBoot <= 6.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-97063Critical· 9.1X-SpringBoot through 6.0 Authentication Bypass via Login Code
CVE-2026-97060High· 7.2X-SpringBoot through 6.0 Authorization Bypass via User Management
CVE-2026-100192Medium· 6.5X-SpringBoot through 6.0 Credential Exposure via Unauthenticated Endpoint
CVE-2026-97649Medium· 4.7A flaw has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf
CVE-2026-90498High· 7.3A vulnerability was identified in lenve vhr 1.0-SNAPSHOT
CVE-2026-90451High· 8.2An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component