CVE-2026-47858
EUVD-2026-5097030.07.2026, 06:25
Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier Spring Tools for VSCode / Cursor / Theia: 2.2.0 and earlierEnginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| broadcom | spring_tools | 𝑥 < 2.3.0 |
| broadcom | spring_tools | 𝑥 < 2.3.0 |
| broadcom | spring_tools | 𝑥 < 2.3.0 |
| broadcom | spring_tools | 𝑥 < 5.3.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration