CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-97063 — X-SpringBoot through 6.0 returns login verification codes in HTTP responses from...

·Source: NIST NVD

Updated:

Executive Summary

X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners. Attackers can request codes using known mobile numbers or email addresses, read them from responses, and authenticate as victims via POST /sys/emailOrMobileLogin/login to hijack accounts.

Analysis

X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners. Attackers can request codes using known mobile numbers or email addresses, read them from responses, and authenticate as victims via POST /sys/emailOrMobileLogin/login to hijack accounts. CVSS Score: 9.1. Published: 2026-09-25T19:17:59.267.

Indicators of Compromise (1)

CVE (1)
CVE-2026-97063
Source Attribution

Originally published by NIST NVD on Sep 25, 2026. Verified by: NIST.

Related Threats

CRITICALVulnerabilityNEW

NVD CRITICAL: CVE-2026-101077 — A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function pr...

A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp Handler. This manipulation causes missing authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-101077
NIST NVD
CRITICALVulnerabilityNEW

NVD CRITICAL: CVE-2026-101076 — A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the func...

A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the file /set_ntp_server_ip.cgi of the component CGI Handler. The manipulation of the argument ntp_ip results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-101076
NIST NVD
MEDIUMVulnerabilityNEW

Still on probation from previous arrest for hacking and extortion, Dutch national is arrested again (1)

In June 2023, DataBreaches reported on the arrest of a young Dutch national who was a highly respected “white hat” by day but also a prolific “black hat.” History seems to have repeated itself. Pepijn van der S. has been arrested once again for criminal activities. The Past Predicted the Present Pepijn van der Stap,... Source

DataBreaches.net