Codecentric's vulnerability footprint centers on Spring Boot Admin, a Java-based application monitoring and management tool, with observed exposure concentrated in code-injection and command-injection weaknesses that reflect the risks of dynamic code execution and shell command handling in administrative interfaces. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Codecentric over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-62242HIGH Spring Boot Admin Server before 4.1.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers to register instances with attacker-controlled heal | Jul 13, 2026 | 8.6 | 35 | NO | NO |
CVE-2022-46166CRITICAL Spring boot admins is an open source administrative user interface for management of spring boot applications. All users who run Spring Boot Admin Server, having enabled Notifiers | Dec 9, 2022 | 9.8 | 31 | NO | NO |
CVE-2023-38286HIGH Thymeleaf through 3.1.1.RELEASE, as used in spring-boot-admin (aka Spring Boot Admin) through 3.1.1 and other products, allows sandbox bypass via crafted HTML. This may be relevant | Jul 14, 2023 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Codecentric.
Media articles that mention a CVE ID that affects a product developed by Codecentric — matched by CVE ID, not by vendor name.