Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 25 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering. Unauthenticated attackers can retrieve these credentials and use them to send arbitrary SMS messages through any tenant's SMS provider, enabling SMS bombing and impersonation attacks. | |
| Title | X-SpringBoot through 6.0 Credential Exposure via Unauthenticated Endpoint | |
| Weaknesses | CWE-306 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-25T18:12:17.702Z
Reserved: 2026-09-25T14:01:31.601Z
Link: CVE-2026-100192
No data.
Status : Received
Published: 2026-09-25T19:16:49.230
Modified: 2026-09-25T19:16:49.230
Link: CVE-2026-100192
No data.
OpenCVE Enrichment
No data.
-
CWE-306
Missing Authentication for Critical Function