Loading market data...
← Back to CVE feed

CVE-2026-100192

MEDIUM CVSS 6.5 View on NVD ↗

Description

X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering. Unauthenticated attackers can retrieve these credentials and use them to send arbitrary SMS messages through any tenant's SMS provider, enabling SMS bombing and impersonation attacks.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Published: Sep 25, 2026 19:16 UTC Modified: Sep 25, 2026 19:16 UTC