CVE-2026-22733

EUVD-2026-13349
Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under the path used by the CloudFoundry Actuator endpoints. This issue affects Spring Security: from 4.0.0 through 4.0.3, from 3.5.0 through 3.5.11, from 3.4.0 through 3.4.14, from 3.3.0 through 3.3.17, from 2.7.0 through 2.7.31.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.2 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 7%
Affected Products (NVD)
VendorProductVersion
vmwarespring_boot
𝑥
< 2.7.32
vmwarespring_boot
3.3.0 ≤
𝑥
< 3.3.18
vmwarespring_boot
3.4.0 ≤
𝑥
< 3.4.15
vmwarespring_boot
3.5.0 ≤
𝑥
< 3.5.12
vmwarespring_boot
4.0.0 ≤
𝑥
< 4.0.4
𝑥
= Vulnerable software versions