Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-22733

Spring Boot Actuator: authentication bypass for endpoints under the Cloud Foundry actuator path

Technology

Spring Boot

CVSS Score

8.1 / 10.0

Affected Versions

4.0.0 to 4.0.3; 3.5.0 to 3.5.11; 3.4.0 to 3.4.14; 3.3.0 to 3.3.17; 2.7.31 and earlier

Upstream Fix

4.0.4, 3.5.12 (public); 3.4.15, 3.3.18, 2.7.32 (Enterprise Support Only)

Published

March 20, 2026

OSSeva Coverage

Fixed upstream

Description

An application endpoint that requires authentication can be reached without it when it is declared under the path used by the Cloud Foundry actuator endpoints, such as /cloudfoundryapplication/admin. The application must be a web application with Actuator and Spring Security on the classpath. Similar to, but not the same as, CVE-2026-22731.

Upstream record: NVD · CVE.org

Is your Spring Boot deployment affected?

If you're running 4.0.0 to 4.0.3; 3.5.0 to 3.5.11; 3.4.0 to 3.4.14; 3.3.0 to 3.3.17; 2.7.31 and earlier, you need this patch. Book a discovery call to get covered.