logo

Two High-Severity Spring Boot Flaws Expose Actuator Endpoints

ID: e39227c3-da9b-58e7-b403-6913dd0e6046

STIX ID: report--e39227c3-da9b-58e7-b403-6913dd0e6046

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-03-20

Date Updated: 2026-04-23

Author: Ddos

...
...

Security researchers disclosed two high-severity authentication-bypass vulnerabilities in Spring Boot Actuator (CVE-2026-22731 and CVE-2026-22733, CVSS 8.2) that can grant unauthorized access when custom application endpoints are mapped under Actuator or CloudFoundry Actuator paths; multiple Spring Boot release branches are affected and mitigations include updating to fixed versions and avoiding mapping application logic under infrastructure endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.