CVE-2026-97060: X-SpringBoot through 6.0 Authorization Bypass via User Management

Published Sep 25, 2026
·
Updated

X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification. Attackers with user-management permissions can reset passwords for any account including the super administrator, rebind roles, or delete users via POST /sys/user/update and POST /sys/user/delete endpoints.

Affected Software

1 affected component
X-SpringBoot<=6.0

Event History

Sep 25, 2026
CVE Published
via MITRE·06:12 PM
Data Sourced
via MITRE·06:12 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker must already have user-management permissions, such as a sub-administrator. No user interaction is required, and the affected endpoints are reachable over the network.

2

What actions could an attacker take through the affected endpoints?

A permitted sub-administrator can modify or delete users without ownership verification. This includes resetting passwords for arbitrary accounts, including the super administrator, rebinding roles, and deleting users via POST /sys/user/update or POST /sys/user/delete.

3

How can I determine whether my deployment is exposed?

Review whether X-SpringBoot is version 6.0 or earlier and whether accounts other than the super administrator have user-management permissions. Test authorization controls on POST /sys/user/update and POST /sys/user/delete to verify that such accounts cannot act on users outside their ownership or intended administrative scope.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203