Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-22731

Spring Boot Actuator: authentication bypass for endpoints under a health group additional path

Technology

Spring Boot

CVSS Score

8.1 / 10.0

Affected Versions

4.0.0 to 4.0.3; 3.5.0 to 3.5.11; 3.4.0 to 3.4.14

Upstream Fix

4.0.4, 3.5.12 (public); 3.4.15 (Enterprise Support Only)

Published

March 19, 2026

OSSeva Coverage

Fixed upstream

Description

An application endpoint that requires authentication can be reached without it when it is declared under a path already configured as a health group's additional path, for example management.endpoint.health.group.mygroup.additional-path=server:/healthz with an authenticated endpoint at /healthz/admin. The application must have Actuator on the classpath and a custom health group exposed on the main server. Spring advises against mapping application endpoints under actuator paths. Similar to, but not the same as, CVE-2026-22733.

Upstream record: NVD · CVE.org

Is your Spring Boot deployment affected?

If you're running 4.0.0 to 4.0.3; 3.5.0 to 3.5.11; 3.4.0 to 3.4.14, you need this patch. Book a discovery call to get covered.