cbcvebase.
CVE-2026-22731
published 2026-03-19

CVE-2026-22731: Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication…

PriorityP355high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.33%
25.4th percentile
Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a specific path, already configured for a Health Group additional path. This issue affects Spring Boot: from 4.0 before 4.0.3, from 3.5 before 3.5.11, from 3.4 before 3.4.15. This CVE is similar but not equivalent to CVE-2026-22733, as the conditions for exploit and vulnerable versions are different.

Affected

6 ranges
VendorProductVersion rangeFixed in
springspring_boot>= 3.4 < 3.4.153.4.15
springspring_boot>= 3.5 < 3.5.113.5.11
springspring_boot>= 4.0 < 4.0.34.0.3
vmwarespring_boot>= 3.4.0 < 3.4.153.4.15
vmwarespring_boot>= 3.5.0 < 3.5.123.5.12
vmwarespring_boot>= 4.0.0 < 4.0.44.0.4

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
ghsa8.2HIGH
osv8.2HIGH
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.