CVE-2026-100192

CVE-2026-100192 published: X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering. Unauthenticated attackers can retrieve these credentials and use them to send arbitrary SMS messages...

View full NVD advisory → ← Back to CVE watch