CVE-2026-22733

HIGH

Authentication Bypass under Actuator CloudFoundry endpoints

Title source: cna
STIX 2.1

Description

Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under the path used by the CloudFoundry Actuator endpoints. This issue affects Spring Security: from 4.0.0 through 4.0.3, from 3.5.0 through 3.5.11, from 3.4.0 through 3.4.14, from 3.3.0 through 3.3.17, from 2.7.0 through 2.7.31.

Scores

CVSS v3 8.2
EPSS 0.0003
EPSS Percentile 7.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-288
Status published
Products (7)
org.springframework.boot/spring-boot-starter-actuator 4.0.0-M1 - 4.0.4Maven
Spring/Spring Security 2.7.0 - 2.7.31
Spring/Spring Security 3.3.0 - 3.3.17
Spring/Spring Security 3.4.0 - 3.4.14
Spring/Spring Security 3.5.0 - 3.5.11
Spring/Spring Security 4.0.0 - 4.0.3
vmware/spring_boot < 2.7.32
Published Mar 20, 2026
Tracked Since Mar 20, 2026