Junglewise Threat Intelligence

CVE-2026-22731: VMware Spring Boot authentication bypass in Actuator Health groups

CVE-2026-22731 · Severity: high · CVSS 8.2 · Published 2026-03-20

Technologies: VMware Spring Boot. Vendors: VMware.

Executive brief

Spring Boot is a popular framework used to build Java-based web applications. A security flaw in its Actuator component—a tool used for monitoring application health—could allow unauthorized users to access protected parts of an application without logging in. This could lead to the exposure of sensitive internal data or unauthorized access to administrative functions.

Technical details

An authentication bypass vulnerability exists in Spring Boot Actuator (CWE-288, CWE-306). The issue occurs when an application endpoint requiring authentication is declared under a specific path that has already been configured as an additional path for a Health Group. Because Health Groups may have different security constraints, an attacker can reach the protected endpoint via the alternate health path without providing credentials. This allows for unauthorized network-based access to sensitive application data. The vulnerability is patched in versions 3.5.12 and 4.0.4.

Affected products

  • VMware Spring Boot 4.0.0-M1 to 4.0.3, 3.5.0 to 3.5.11, 3.4.0 to 3.4.14

Timeline

  • 2026-03-19: advisory: NVD Published Date
  • 2026-03-20: disclosed: GitHub Advisory published
  • 2026-04-16: other: Last updated

References

Related threats