CVE-2026-22733
Spring Boot Actuator: authentication bypass for endpoints under the Cloud Foundry actuator path
Technology
Spring Boot
CVSS Score
8.1 / 10.0
Affected Versions
4.0.0 to 4.0.3; 3.5.0 to 3.5.11; 3.4.0 to 3.4.14; 3.3.0 to 3.3.17; 2.7.31 and earlier
Upstream Fix
4.0.4, 3.5.12 (public); 3.4.15, 3.3.18, 2.7.32 (Enterprise Support Only)
Published
March 20, 2026
OSSeva Coverage
Fixed upstream
Description
An application endpoint that requires authentication can be reached without it when it is declared under the path used by the Cloud Foundry actuator endpoints, such as /cloudfoundryapplication/admin. The application must be a web application with Actuator and Spring Security on the classpath. Similar to, but not the same as, CVE-2026-22731.
Is your Spring Boot deployment affected?
If you're running 4.0.0 to 4.0.3; 3.5.0 to 3.5.11; 3.4.0 to 3.4.14; 3.3.0 to 3.3.17; 2.7.31 and earlier, you need this patch. Book a discovery call to get covered.