CVE-2026-22733Disclosure(vmware / spring_boot)

LOWCVSS 8.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch vmware spring_boot systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under the path used by the CloudFoundry Actuator endpoints. This issue affects Spring Security: from 4.0.0 through 4.0.3, from 3.5.0 through 3.5.11, from 3.4.0 through 3.4.14, from 3.3.0 through 3.3.17, from 2.7.0 through 2.7.31.

2.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-288

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • spring_boot

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-03-20); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
spring_boot

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-03-20: 3Mentions · 2026-03-23: 1Mentions · 2026-03-26: 1Mentions · 2026-05-15: 1PoC Mentioned / Linked · 2026-05-15: 1Patch / Workaround · 2026-03-20: 2Technical Details · 2026-03-20: 3Technical Details · 2026-05-15: 103-2003-2303-2605-15
Signal classification2 categories
Disclosure
583.3%
General
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-203
Disclosure3
2026-03-231
General1
2026-03-261
Disclosure1
2026-05-151
Disclosure1
Full discourse6 posts
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Spring ❗ CVE-2026-22733 ❗ CVE-2026-22732 ❗ CVE-2026-22731 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-spring-2/ https://t.co/p95JH7QS4Y

    Post summary

    The tweet lists three CVE identifiers for Spring products and links to a website for additional information, but provides no details on exploitation, patches, or technical specifics.

    01011108
    6.6K followersView on X
  • Gray Hats@the_yellow_fall
    Disclosure

    Two high-severity flaws (CVE-2026-22731 & CVE-2026-22733) in Spring Boot Actuators allow authentication bypass. Update your framework today to stay secure. #SpringBoot #CyberSecurity #CVE #InfoSec #AppSec #AuthenticationBypass #Vulnerability #JavaSecurity https://securityonline.info/spring-boot-authentication-bypass-actuator-flaws-cve-2026-22731/ https://t.co/DhnFNBWhk9

    Post summary

    Two newly disclosed CVEs (CVE‑2026‑22731 & CVE‑2026‑22733) in Spring Boot Actuators allow authentication bypass; the tweet urges users to update their framework to mitigate the risk.

    00011262
    10.7K followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-22733 | VMware Spring Security up to 4.0.3 CloudFoundry Actuator Endpoint authentication bypass (WID-SEC-2026-0799) https://ift.tt/blyqVg3 A vulnerability, which was classified as critical, was found in VMware Spring Security up to 2.7.31/3.3.17/3.4.14/3.5.11/4.0.3. T…

    Post summary

    A critical authentication bypass vulnerability (CVE-2026-22733) affects VMware Spring Security versions up to 4.0.3, with a link to further details but no indications of active exploitation or remediation.

    0000050
    974 followersView on X
  • HeroDevs@herodevs
    Disclosure

    Learn more 🔗 https://www.herodevs.com/blog-posts/spring-boot-authentication-bypass-two-new-cves-that-enterprise-teams-cannot-afford-to-ignore-cve-2026-22731-cve-2026-22733

    Post summary

    The text announces the discovery of two new Spring Boot authentication‑bypass CVEs (CVE‑2026‑22731 and CVE‑2026‑22733) and provides a link to a blog post for further details.

    0000065
    2.7K followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: High severity Authentication Bypass flaws in Spring Boot Actuator. #CVE-2026-22731 & #CVE-2026-22733, CVSS: 8.2. Misconfigured endpoint paths can expose protected application endpoints. #Patch #Patch #Patch

    Post summary

    The post warns of authentication bypass flaws in Spring Boot Actuator, citing CVE-2026-22731 & CVE-2026-22733 with CVSS 8.2, and urges users to apply patches.

    00000186
    7.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22733 Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is decl… https://www.cve.org/CVERecord?id=CVE-2026-22733

    Post summary

    The post announces CVE‑2026‑22733 as an authentication‑bypass issue in Spring Boot Actuator, without providing proof of concept, exploit code, patch information, or evidence of active attacks.

    00000122
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarespring_boot---

Explore more