Two High-Severity Spring Boot Flaws Expose Actuator Endpoints
ID: e39227c3-da9b-58e7-b403-6913dd0e6046
STIX ID: report--e39227c3-da9b-58e7-b403-6913dd0e6046
Feed Name: securityonline.info
Threat Score
Security researchers disclosed two high-severity authentication-bypass vulnerabilities in Spring Boot Actuator (CVE-2026-22731 and CVE-2026-22733, CVSS 8.2) that can grant unauthorized access when custom application endpoints are mapped under Actuator or CloudFoundry Actuator paths; multiple Spring Boot release branches are affected and mitigations include updating to fixed versions and avoiding mapping application logic under infrastructure endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
