External risk intelligence

X-SpringBoot Authentication Bypass Via Exposed Login Codes

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-97063

The vulnerability affects login and authentication endpoints within a web application framework. These endpoints are designed to be accessible to users over the internet to facilitate account login, making them a common part of the public-facing attack surface for web services.

Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability in X-SpringBoot could allow attackers to intercept login verification codes and hijack user accounts. The issue arises when unauthenticated endpoints return these codes in HTTP responses, enabling unauthorized access. The main concern is confirming relevance and exposure for our systems.

  • Codes are returned in responses, bypassing security.
  • Account hijacking is possible without prior access.
  • Confirm if our systems are affected by this.

Attack Path

How an attacker could exploit the issue

An attacker can initiate an account takeover by exploiting unauthenticated endpoints that return login verification codes. The attacker would first discover or obtain a victim's mobile number or email address. They then make requests to specific endpoints to retrieve the verification code, which is improperly sent back in the HTTP response. With this code, the attacker can authenticate as the victim on a different endpoint and hijack the account.

  • Entry condition: No authentication required.
  • Trigger point: Requesting verification codes from specific endpoints.
  • Resulting risk: Account takeover.

Live Threat

Current exploitation, exposure, and threat context

Attackers could hijack user accounts by intercepting login verification codes. This is possible when the application returns these codes in HTTP responses from unauthenticated endpoints, allowing an attacker to request a code for a known mobile number or email address and then use it to log in as the victim.

  • User accounts and authentication tokens
  • Intercepting verification codes from HTTP responses
  • Unauthorized account access and control

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts systems using X-SpringBoot, potentially exposing login verification codes. Infrastructure and application teams should collaborate to identify affected systems, determine their criticality and exposure, and plan remediation.

  • Owning teams: Application and Infrastructure.
  • Verify first: System reachability and business criticality.
  • Action: Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is X-SpringBoot?

X-SpringBoot is a web application framework used to build enterprise-grade software. It typically provides built-in modules for managing user identity and authentication processes. By acting as the foundation for these login systems, it handles the logic for verifying users via email or mobile phone numbers before granting access to the application's protected features.

What does CVE-2026-97063 mean for security?

This vulnerability is classified as Improper Authentication (CWE-287). It means the software fails to properly verify who is requesting a login code. Instead of keeping the verification secret or sending it directly to the user's private device, the system mistakenly hands the code back to anyone who asks for it via an unauthenticated web request.

How is this vulnerability triggered?

An attacker triggers this by sending a request to specific login endpoints for a target's email or mobile number. The system responds by including the secret code in the message body. Importantly, this bug only occurs if the system is configured to process these requests; it is not triggered by simply visiting the main homepage or performing legitimate actions.

Is my system at risk according to Halo Surface Signal?

Halo Surface Signal identifies that this vulnerability affects web-based authentication endpoints. Because these endpoints must be reachable over the internet to allow users to log in, any system running an affected version of X-SpringBoot is considered part of the public-facing attack surface and is potentially reachable by unauthorized actors.

What should I do if I use X-SpringBoot?

Begin by working with your application and infrastructure teams to perform an inventory of all systems running X-SpringBoot. Once identified, evaluate the business criticality and network exposure of these instances. Prioritize blocking access to the specific unauthenticated endpoints involved in code generation while you coordinate with developers to apply the necessary security updates.

References