External risk intelligence

X-SpringBoot Authentication Bypass via Static Master Code.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-97064

The vulnerability resides in an authentication endpoint of a web application. Such login services are commonly exposed to the internet to allow remote user access, making this type of web-based authentication surface a frequent candidate for public network reachability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical authentication bypass vulnerability in X-SpringBoot. The issue stems from a hardcoded default master login code that, if exploited, allows unauthenticated attackers to gain access as any user by submitting this code along with a known email or mobile number. The primary concern at this time is to confirm if our environment uses this specific technology and is therefore exposed.

  • Hardcoded code bypasses user authentication.
  • Critical access flaw impacts many users.
  • Confirm relevance and exposure immediately.

Attack Path

How an attacker could exploit the issue

Attackers can exploit this vulnerability by sending a request to the `emailOrMobileLogin` endpoint without needing any prior authentication. This is possible because the application uses a hardcoded, static master code for verification, which is publicly known and enabled by default. By providing this code along with a known email or mobile number, an unauthenticated attacker can impersonate any user.

  • No authentication required.
  • Submitting public master code to login endpoint.
  • Unauthorized access to any user account.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, unauthenticated attackers could bypass authentication to impersonate any user by leveraging a hardcoded master login code within the database seed. This could affect access to user accounts and associated service data.

  • User account access.
  • Submitting a public master code.
  • Unauthorized access and data exposure.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in X-SpringBoot's authentication mechanism requires immediate attention from application owners and infrastructure teams. The primary next step is to identify all instances of X-SpringBoot, confirm their exposure and criticality, and then coordinate remediation efforts with the accountable owners to mitigate the risk of unauthorized access.

  • Identify application owners and systems.
  • Verify system exposure and business criticality.
  • Plan risk-based remediation actions.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is X-SpringBoot?

X-SpringBoot is a software framework built on Spring Boot that provides pre-configured modules for web applications. Developers use it to accelerate the development of systems requiring user management and authentication features. This vulnerability specifically affects the codebase versions up to 6.0, which includes database seeds containing pre-set configuration values for initial deployment.

What is the security weakness in CVE-2026-97064?

This vulnerability is classified as CWE-1392, which involves the use of hardcoded credentials. In this instance, a static master verification code is embedded directly into the application's default database configuration. Because this code is universal and static, it functions as a universal key that bypasses the intended login security checks.

How can an attacker trigger this vulnerability?

An attacker triggers the flaw by sending a request to the emailOrMobileLogin endpoint using the known master code instead of a valid user-specific credential. No prior interaction, session, or account knowledge is required beyond having a target's email or mobile number. Providing a random or empty password does not trigger this; the exploit relies specifically on submitting the correct, hardcoded master code.

Why is this relevant to my infrastructure?

According to Halo Surface Signal, this vulnerability impacts a web-based authentication endpoint that is frequently placed on the public internet to facilitate remote user access. Because login services are inherently designed to be reachable, systems running X-SpringBoot are highly likely to be exposed to network-based attacks if they are not restricted to internal-only access.

What are the first steps to address this issue?

Begin by inventorying your environment to locate all active instances of X-SpringBoot. Once identified, evaluate whether these applications are internet-facing or contain sensitive user data. Coordinate with your application owners to prioritize these systems for remediation, as this flaw grants complete unauthorized access to any user account within the affected application.

References