CVE-2026-100192: X-SpringBoot through 6.0 Credential Exposure via Unauthenticated Endpoint

Published Sep 25, 2026
·
Updated

X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering. Unauthenticated attackers can retrieve these credentials and use them to send arbitrary SMS messages through any tenant's SMS provider, enabling SMS bombing and impersonation attacks.

Affected Software

1 affected component
X-SpringBoot<=6.0

Event History

Sep 25, 2026
CVE Published
via MITRE·06:12 PM
Data Sourced
via MITRE·06:12 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any unauthenticated remote attacker who can reach the application's GET /application/manager/select endpoint can retrieve exposed appKey and appSecret credentials. No prior account or user interaction is required.

2

What could an attacker do with the exposed credentials?

The credentials can be used to send arbitrary SMS messages through any tenant's configured SMS provider. This enables SMS bombing and messages that impersonate the affected tenant.

3

Which deployments are affected?

X-SpringBoot through version 6.0 is affected where the vulnerable endpoint is reachable. The issue is present because the endpoint lacks authentication and field filtering.

4

How can I check whether an instance is exposed?

Verify whether GET /application/manager/select is reachable without authentication and whether its response includes appKey or appSecret values. Exposure of either credential field indicates the endpoint is disclosing SMS-provider credentials.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203