V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2026-22733
DEB
High

Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requ…

CVSS
8.1
High
EPSS
0.00
p27
Published
2026-01-01
Updated
2026-01-01
Description

Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under the path used by the CloudFoundry Actuator endpoints. This issue affects Spring Security: from 4.0.0 through 4.0.3, from 3.5.0 through 3.5.11, from 3.4.0 through 3.4.14, from 3.3.0 through 3.3.17, from 2.7.0 through 2.7.31.

Tags · CWE
Pre-authAuth bypass
CWE-288
CAPEC-127
CAPEC-665
Affected products
Spring_boot < 2.7.32Spring_boot 3.3.0–3.3.18Spring_boot 3.4.0–3.4.15Spring_boot 3.5.0–3.5.12Spring_boot 4.0.0–4.0.4
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2026-01-01
Published
2026-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.004 · p27
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-127 · CWE-288
└ via CAPEC-665 · CWE-288
└ via CAPEC-665 · CWE-288
└ via CAPEC-665 · CWE-288
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
libspring-security-2.0-javaTracked
spring_boot*Tracked
Source databases
DEB
CVE