Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 25 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as any user by submitting the public master code to the emailOrMobileLogin endpoint with a known email or mobile number. | |
| Title | X-SpringBoot through 6.0 Authentication Bypass via Static Master Code | |
| Weaknesses | CWE-1392 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-25T18:12:19.819Z
Reserved: 2026-09-23T23:51:32.671Z
Link: CVE-2026-97064
No data.
Status : Received
Published: 2026-09-25T19:17:59.427
Modified: 2026-09-25T19:17:59.427
Link: CVE-2026-97064
No data.
OpenCVE Enrichment
No data.