CVE-2026-22733 PUBLISHED

Authentication Bypass under Actuator CloudFoundry endpoints

Assigner: vmware
Reserved: 09.01.2026 Published: 19.03.2026 Updated: 20.03.2026

Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under the path used by the CloudFoundry Actuator endpoints. This issue affects Spring Security: from 4.0.0 through 4.0.3, from 3.5.0 through 3.5.11, from 3.4.0 through 3.4.14, from 3.3.0 through 3.3.17, from 2.7.0 through 2.7.31.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CVSS Score: 8.2

Product Status

Vendor Spring
Product Spring Security
Versions Default: unaffected
  • affected from 4.0.0 to 4.0.3 (incl.)
  • affected from 3.5.0 to 3.5.11 (incl.)
  • affected from 3.4.0 to 3.4.14 (incl.)
  • affected from 3.3.0 to 3.3.17 (incl.)
  • affected from 2.7.0 to 2.7.31 (incl.)

References

Problem Types

  • CWE-288 Authentication bypass using an alternate path or channel CWE