CVE-2026-100192: YZCHENG90 X-Springboot

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering. Unauthenticated attackers can retrieve these credentials and use them to send arbitrary SMS messages through any tenant's SMS provider, enabling SMS bombing and impersonation attacks.

Affected products

  • YZCHENG90 X-Springboot: up to and including 6.0

Published 2026-09-25. Last modified 2026-09-29.