OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-97064 (CVSS 9.3)

NVD · officialPublished Sep 25, 2026Risk 50/100

X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as any user by submitting the public master code to the emailOrMobileLogin endpoint with a known email or mobile number.

CVSS
9.3
AV:NetworkAC:LowPR:NoneUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source