← Back

CVE-2026-22731

nvd nist
Published: Mar 19, 2026Modified: Jun 17, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a specific path, already configured for a Health Group additional path. This issue affects Spring Boot: from 4.0 before 4.0.3, from 3.5 before 3.5.11, from 3.4 before 3.4.15. This CVE is similar but not equivalent to CVE-2026-22733, as the conditions for exploit and vulnerable versions are different.

Affected (3)

Products: Vmware: Spring Boot
1 product
Spring Boot
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Vmware
From 3.4.0 to 3.4.15
From 3.5.0 to 3.5.12
From 4.0.0 to 4.0.4

References (1)

Source: security@vmware.com
Vendor Advisory

Timeline

No history available yet.