{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-100192","assignerOrgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","state":"PUBLISHED","assignerShortName":"VulnCheck","dateReserved":"2026-09-25T14:01:31.601Z","datePublished":"2026-09-25T18:12:17.702Z","dateUpdated":"2026-09-29T19:38:51.593Z"},"containers":{"cna":{"providerMetadata":{"orgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","shortName":"VulnCheck","dateUpdated":"2026-09-25T18:12:17.702Z"},"datePublic":"2026-09-09T00:00:00.000Z","title":"X-SpringBoot through 6.0 Credential Exposure via Unauthenticated Endpoint","descriptions":[{"lang":"en","value":"X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering. Unauthenticated attackers can retrieve these credentials and use them to send arbitrary SMS messages through any tenant's SMS provider, enabling SMS bombing and impersonation attacks."}],"problemTypes":[{"descriptions":[{"lang":"en","description":"Missing Authentication for Critical Function","cweId":"CWE-306","type":"CWE"}]}],"affected":[{"vendor":"yzcheng90","product":"X-SpringBoot","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"6.0","status":"affected","versionType":"custom"}],"packageURL":"pkg:github/yzcheng90/X-SpringBoot","repo":"https://github.com/yzcheng90/X-SpringBoot"}],"metrics":[{"format":"CVSS","cvssV4_0":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","baseScore":6.9,"baseSeverity":"MEDIUM"}},{"format":"CVSS","cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}],"references":[{"url":"https://github.com/LinYuanyi1/cve-request-poc/blob/master/x-springboot/01_app-credential-sms-abuse.py","tags":["exploit"],"name":"Proof of concept"},{"url":"https://github.com/yzcheng90/X-SpringBoot/blob/d74ddba989c0449948ff1ddb0d211b6a7ce81bfa/src/main/java/com/suke/czx/modules/application/controller/XApplicationController.java#L59-L64","tags":["technical-description"],"name":"Vulnerable code"},{"url":"https://github.com/yzcheng90/X-SpringBoot","tags":["product"]},{"name":"VulnCheck Advisory: X-SpringBoot through 6.0 Credential Exposure via Unauthenticated Endpoint","tags":["third-party-advisory"],"url":"https://www.vulncheck.com/advisories/x-springboot-through-6.0-credential-exposure-via-unauthenticated-endpoint"}],"credits":[{"lang":"en","value":"Yaqi Chao","type":"finder"},{"lang":"en","value":"Mingsheng Lin","type":"finder"}],"x_generator":{"engine":"vulncheck-endgame"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-29T19:38:37.267264Z","id":"CVE-2026-100192","options":[{"Exploitation":"poc"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-29T19:38:51.593Z"}}]}}