CVE-2026-22731 describes an authentication bypass vulnerability affecting Spring Boot applications utilizing Actuator, specifically versions 4.0.x (before 4.0.3), 3.5.x (before 3.5.11), and 3.4.x (before 3.4.15). This high-severity flaw (CVSS 8.2) allows unauthenticated attackers to gain unauthorized access to application endpoints declared under specific Health Group paths. Exploitation is network-based, requires no user interaction or prior privileges, and has low attack complexity, potentially leading to high confidentiality and low integrity impacts. Currently, there is no evidence of active exploitation or public exploit code, though it has received limited community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.4.0, < 3.4.15CPE matchmatch criteria | cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:* | ||
>= 3.5.0, < 3.5.12CPE matchmatch criteria | cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:* | ||
>= 4.0.0, < 4.0.4CPE matchmatch criteria | cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.