X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering. Unauthenticated attackers can retrieve these credentials and use them to send arbitrary SMS messages through any tenant's SMS provider, enabling SMS bombing and impersonation attacks.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 25 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering. Unauthenticated attackers can retrieve these credentials and use them to send arbitrary SMS messages through any tenant's SMS provider, enabling SMS bombing and impersonation attacks. | |
| Title | X-SpringBoot through 6.0 Credential Exposure via Unauthenticated Endpoint | |
| Weaknesses | CWE-306 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-25T18:12:17.702Z
Reserved: 2026-09-25T14:01:31.601Z
Link: CVE-2026-100192
No data.
Status : Received
Published: 2026-09-25T19:16:49.230
Modified: 2026-09-25T19:16:49.230
Link: CVE-2026-100192
No data.
OpenCVE Enrichment
Updated: 2026-09-25T20:00:10Z
Weaknesses