X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering. Unauthenticated attackers can retrieve these credentials and use them to send arbitrary SMS messages through any tenant's SMS provider, enabling SMS bombing and impersonation attacks.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 26 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yzcheng90
Yzcheng90 x-springboot |
|
| Vendors & Products |
Yzcheng90
Yzcheng90 x-springboot |
Fri, 25 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering. Unauthenticated attackers can retrieve these credentials and use them to send arbitrary SMS messages through any tenant's SMS provider, enabling SMS bombing and impersonation attacks. | |
| Title | X-SpringBoot through 6.0 Credential Exposure via Unauthenticated Endpoint | |
| Weaknesses | CWE-306 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-25T18:12:17.702Z
Reserved: 2026-09-25T14:01:31.601Z
Link: CVE-2026-100192
No data.
Status : Received
Published: 2026-09-25T19:16:49.230
Modified: 2026-09-25T19:16:49.230
Link: CVE-2026-100192
No data.
OpenCVE Enrichment
Updated: 2026-09-26T10:30:09Z
Weaknesses