Junglewise Threat Intelligence

CVE-2026-47882: VMware Spring Tools for Eclipse weak PRNG in DevTools shared secret generation

CVE-2026-47882 · Severity: high · CVSS 8.3 · Published 2026-07-30

Vendors: VMware.

Executive brief

Spring Tools for Eclipse, a development environment for building Java applications, contains a security flaw in how it handles remote application updates. When developers use the tool to manage applications running in environments like Docker or Cloud Foundry, it generates a security password that is too easy for an attacker to guess. If an attacker successfully predicts this password, they could upload and execute their own code on the remote application, potentially leading to a full system takeover.

Technical details

Spring Tools for Eclipse (versions 5.2.0 and earlier) utilizes a non-cryptographic pseudo-random number generator (PRNG) to create the shared secret used for authenticating DevTools remote-restart uploads. When DevTools support is enabled for remote targets such as Docker containers or Cloud Foundry apps via the Spring Tools Boot Dashboard, the resulting weak entropy makes the secret susceptible to brute-force or prediction attacks. An attacker with adjacent network access could exploit this to authenticate as a legitimate developer and upload malicious code to the deployed application. The vulnerability is addressed in newer versions by migrating to a cryptographically secure source of randomness.

Affected products

  • VMware Spring Tools for Eclipse 5.2.0 and earlier

Timeline

  • 2026-07-30: disclosed: Initial advisory publication
  • 2026-07-30: advisory: VMware published security advisory CVE-2026-47882

References