OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-97060

HIGH · CVSS 7.2 EPSS 0.31% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

X-SpringBoot versions up to 6.0 are vulnerable due to insufficient object-level authorization in user management endpoints, enabling sub-administrators to modify or delete user accounts without proper ownership verification. This flaw allows attackers with user-management permissions to reset passwords for any account, including super administrators, and to alter or delete user roles. Organizations utilizing X-SpringBoot should prioritize patching this vulnerability to prevent unauthorized access and potential account takeovers.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-97060
Severity
HIGH
CVSS
7.2
EPSS
0.31%

Original NVD Description

X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification. Attackers with user-management permissions can reset passwords for any account including the super administrator, rebind roles, or delete users via POST /sys/user/update and POST /sys/user/delete endpoints.