CVE-2026-22731
Spring Boot Actuator: authentication bypass for endpoints under a health group additional path
Technology
Spring Boot
CVSS Score
8.1 / 10.0
Affected Versions
4.0.0 to 4.0.3; 3.5.0 to 3.5.11; 3.4.0 to 3.4.14
Upstream Fix
4.0.4, 3.5.12 (public); 3.4.15 (Enterprise Support Only)
Published
March 19, 2026
OSSeva Coverage
Fixed upstream
Description
An application endpoint that requires authentication can be reached without it when it is declared under a path already configured as a health group's additional path, for example management.endpoint.health.group.mygroup.additional-path=server:/healthz with an authenticated endpoint at /healthz/admin. The application must have Actuator on the classpath and a custom health group exposed on the main server. Spring advises against mapping application endpoints under actuator paths. Similar to, but not the same as, CVE-2026-22733.
Is your Spring Boot deployment affected?
If you're running 4.0.0 to 4.0.3; 3.5.0 to 3.5.11; 3.4.0 to 3.4.14, you need this patch. Book a discovery call to get covered.