Junglewise Threat Intelligence

CVE-2026-82265: Zipkin Spring Boot Actuator auth bypass on tracing API port

CVE-2026-82265 · Severity: medium · CVSS 6.5 · Published 2026-08-28

Executive brief

Zipkin is a distributed tracing system used to monitor and debug requests flowing through microservices. Versions through 3.6.1 expose administrative Spring Boot Actuator endpoints on the main tracing API port without authentication, allowing anyone with network access to read sensitive configuration data (environment variables, database credentials, bean configurations) and modify system settings like log levels.

Technical details

The vulnerability is an authentication bypass in which Spring Boot Actuator endpoints are exposed and accessible via the tracing API port without credential validation. Attackers can reach these endpoints over the network (no authentication required) and exploit them to extract sensitive information such as environment variables and storage credentials, or manipulate system behavior by changing log levels to suppress audit trails. The root cause is improper endpoint configuration or missing authentication guards on the Actuator interface. The vulnerability affects Zipkin versions through 3.6.1. A fix requires upgrading to a patched version that properly restricts Actuator endpoint access.

Affected products

  • Zipkin Zipkin through 3.6.1

Timeline

  • 2026-08-28: disclosed

References