CVE-2026-62242

HIGH

Spring Boot Admin Server < 4.1.2 SSRF via Unauthenticated Instance Registration

Title source: cna
STIX 2.1

Description

Spring Boot Admin Server before 4.1.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers to register instances with attacker-controlled healthUrl and managementUrl parameters without validation against private IP ranges or metadata endpoints. Attackers can force the server to make HTTP requests to arbitrary internal addresses and retrieve response bodies via the actuator proxy to exfiltrate cloud credentials.

References (5)

Core 5

Scores

CVSS v3 8.6
EPSS 0.0028
EPSS Percentile 20.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (1)
codecentric/spring-boot-admin < 4.1.2
Published Jul 13, 2026
Tracked Since Jul 14, 2026