Credential Exposure Vulnerability in X-SpringBoot by YZ Cheng
CVE-2026-100192
Key Information:
- Vendor
Yzcheng90
- Status
- Vendor
- CVE Published:
- 25 September 2026
Badges
What is CVE-2026-100192?
X-SpringBoot up to version 6.0 has a vulnerability in its application manager functionality that exposes sensitive appKey and appSecret credentials via an unauthenticated GET request. The flaw allows unauthorized attackers to access these credentials through the /application/manager/select endpoint, enabling them to dispatch arbitrary SMS messages using any associated tenant's SMS provider. This could lead to severe consequences like SMS bombing and impersonation attacks without proper safeguards.
Affected Version(s)
X-SpringBoot 0 <= 6.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
