CVE-2026-22731Disclosure(vmware / spring_boot)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch vmware spring_boot systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a specific path, already configured for a Health Group additional path. This issue affects Spring Boot: from 4.0 before 4.0.3, from 3.5 before 3.5.11, from 3.4 before 3.4.15. This CVE is similar but not equivalent to CVE-2026-22733, as the conditions for exploit and vulnerable versions are different.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-288CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • spring_boot

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 8 signals
  • Disclosure: 7 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 5 mentions (2026-03-20); latest day: 1
  • 10 total mentions across 5 days

Affected systems

Vendors
Products
spring_boot

Deep dive

Activity timeline10 mentions / 5d
01345Mentions · 2026-03-19: 1Mentions · 2026-03-20: 5Mentions · 2026-03-23: 1Mentions · 2026-03-26: 2Mentions · 2026-05-15: 1Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-19: 1Technical Details · 2026-03-20: 5Technical Details · 2026-03-26: 1Technical Details · 2026-05-15: 103-1903-2003-2303-2605-15
Signal classification3 categories
Disclosure
770.0%
Patch
220.0%
General
110.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-191
Disclosure1
2026-03-205
Disclosure4Patch1
2026-03-231
Disclosure1
2026-03-262
General1Patch1
2026-05-151
Disclosure1
Full discourse10 posts
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Spring ❗ CVE-2026-22733 ❗ CVE-2026-22732 ❗ CVE-2026-22731 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-spring-2/ https://t.co/p95JH7QS4Y

    Post summary

    The post lists three Spring product CVEs (CVEs-2026-22733, 22732, 22731) and points readers to external links for additional information.

    01011108
    6.6K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Two high-severity flaws (CVE-2026-22731 & CVE-2026-22733) in Spring Boot Actuators allow authentication bypass. Update your framework today to stay secure. #SpringBoot #CyberSecurity #CVE #InfoSec #AppSec #AuthenticationBypass #Vulnerability #JavaSecurity https://securityonline.info/spring-boot-authentication-bypass-actuator-flaws-cve-2026-22731/ https://t.co/DhnFNBWhk9

    Post summary

    High‑severity authentication bypass vulnerabilities (CVE-2026-22731 and CVE-2026-22733) in Spring Boot Actuator are disclosed; users are urged to update the framework, with no PoC, exploit, or active exploitation reported.

    00011262
    10.7K followersView on X
  • HeroDevs@herodevs
    Patch

    🚨 New CVE Alert: CVE-2026-22731 (High Severity) 🚨 A newly disclosed vulnerability in Spring Boot Actuator can allow authentication bypass under specific path configurations — meaning protected endpoints may be exposed without credentials. Here’s the risk: → Exploitable over the network with no authentication required → Triggered by how endpoints are mapped under health group paths → Can expose sensitive data or functionality behind what should be secured endpoints Affected versions include: → Spring Boot 3.4 < 3.4.15 → Spring Boot 3.5 < 3.5.11 → Spring Boot 4.0 < 4.0.3 HeroDevs Never-Ending Support (NES) for Spring provides ongoing security patches for EOL versions, helping teams stay secure without forcing immediate migrations. Security gaps don’t always come from code you wrote — sometimes they come from paths you didn’t expect. #SpringBoot #Java #CVE #AppSec #OpenSourceSecurity #DevSecOps #HeroDevs

    Post summary

    CVE-2026-22731 is a high‑severity authentication bypass in Spring Boot Actuator vulnerable in specific version ranges, with available patches from HeroDevs’ EOL support.

    10000160
    2.7K followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-22731 | VMware Spring Boot up to 3.4.14/3.5.10/4.0.2 Actuator Health Group authentication bypass (WID-SEC-2026-0799) https://ift.tt/dF2fj7r A vulnerability, which was classified as critical, was found in VMware Spring Boot up to 3.4.14/3.5.10/4.0.2. The impacted eleme…

    Post summary

    The post announces a critical authentication bypass vulnerability in VMware Spring Boot (Actuator Health Group) with technical details, but provides no evidence of active exploitation, PoC, or patch information.

    0000046
    974 followersView on X
  • HeroDevs@herodevs
    General

    Learn more 🔗 https://www.herodevs.com/blog-posts/spring-boot-authentication-bypass-two-new-cves-that-enterprise-teams-cannot-afford-to-ignore-cve-2026-22731-cve-2026-22733

    Post summary

    A brief link‑sharing tweet references two CVEs (CVE-2026-22731 and CVE-2026-22733) but provides no additional details about exploitation, patches, or vulnerability specifics.

    0000065
    2.7K followersView on X
  • CrowdCyber 🌐@CrowdCyber_Com
    Disclosure

    Two High-Severity Spring Boot Flaws Expose Actuator Endpoints https://securityonline.info/spring-boot-authentication-bypass-actuator-flaws-cve-2026-22731/

    Post summary

    The article announces two high-severity Spring Boot vulnerabilities that expose actuator endpoints, but it does not provide details on patches, exploits, or active exploitation.

    0000038
    298 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: High severity Authentication Bypass flaws in Spring Boot Actuator. #CVE-2026-22731 &amp; #CVE-2026-22733, CVSS: 8.2. Misconfigured endpoint paths can expose protected application endpoints. #Patch #Patch #Patch

    Post summary

    The tweet warns of high‑severity authentication bypass vulnerabilities in Spring Boot Actuator (CVE‑2026‑22731 and CVE‑2026‑22733) with a CVSS of 8.2, but gives no PoC, exploit, or patch details.

    00000186
    7.2K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-22731 Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is decl… https://www.cve.org/CVERecord?id=CVE-2026-22731 ----- Traducción: CVE-2026-22731 Las… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑22731, an authentication‑bypass flaw in Spring Boot Actuator, providing only a brief vulnerability type and a link to the official record.

    0000048
    61 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22731 Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is decl… https://www.cve.org/CVERecord?id=CVE-2026-22731

    Post summary

    The statement notes that CVE-2026-22731 is an authentication bypass flaw in Spring Boot Actuator, referencing its CVE record for details.

    00000219
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-22731 - High Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a specific pat... https://www.thehackerwire.com/vulnerability/CVE-2026-22731/ https://t.co/bh3RsuK6NW

    Post summary

    The post announces a high‑severity authentication bypass vulnerability (CVE‑2026‑22731) affecting Spring Boot Actuator endpoints, describing the issue but not providing patches, PoCs, or evidence of active exploitation.

    0000058
    137 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarespring_boot---

Explore more