CVE-2026-22731
published 2026-03-19CVE-2026-22731: Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication…
PriorityP355high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.33%
25.4th percentile
Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a specific path, already configured for a Health Group additional path.
This issue affects Spring Boot: from 4.0 before 4.0.3, from 3.5 before 3.5.11, from 3.4 before 3.4.15.
This CVE is similar but not equivalent to CVE-2026-22733, as the conditions for exploit and vulnerable versions are different.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring | spring_boot | >= 3.4 < 3.4.15 | 3.4.15 |
| spring | spring_boot | >= 3.5 < 3.5.11 | 3.5.11 |
| spring | spring_boot | >= 4.0 < 4.0.3 | 4.0.3 |
| vmware | spring_boot | >= 3.4.0 < 3.4.15 | 3.4.15 |
| vmware | spring_boot | >= 3.5.0 < 3.5.12 | 3.5.12 |
| vmware | spring_boot | >= 4.0.0 < 4.0.4 | 4.0.4 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
ghsa8.2HIGH
osv8.2HIGH
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Spring Boot has an Authentication Bypass under Actuator Health groups paths
ghsa·2026-03-20·CVSS 8.2
CVE-2026-22731 [HIGH] CWE-288 Spring Boot has an Authentication Bypass under Actuator Health groups paths
Spring Boot has an Authentication Bypass under Actuator Health groups paths
Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a specific path, already configured for a Health Group additional path.
This issue affects Spring Boot: from 4.0 before 4.0.3, from 3.5 before 3.5.11, from 3.4 before 3.4.15.
This CVE is similar but not equivalent to CVE-2026-22733, as the conditions for exploit and vulnerable versions are different.
OSV
Spring Boot has an Authentication Bypass under Actuator Health groups paths
osv·2026-03-20·CVSS 8.2
CVE-2026-22731 [HIGH] Spring Boot has an Authentication Bypass under Actuator Health groups paths
Spring Boot has an Authentication Bypass under Actuator Health groups paths
Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a specific path, already configured for a Health Group additional path.
This issue affects Spring Boot: from 4.0 before 4.0.3, from 3.5 before 3.5.11, from 3.4 before 3.4.15.
This CVE is similar but not equivalent to CVE-2026-22733, as the conditions for exploit and vulnerable versions are different.
Red Hat
Spring Boot: Spring Boot: Authentication bypass via misconfigured Health Group additional path
vendor_redhat·2026-03-19·CVSS 8.2
CVE-2026-22731 [HIGH] CWE-305 Spring Boot: Spring Boot: Authentication bypass via misconfigured Health Group additional path
Spring Boot: Spring Boot: Authentication bypass via misconfigured Health Group additional path
Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a specific path, already configured for a Health Group additional path.
This issue affects Spring Boot: from 4.0 before 4.0.3, from 3.5 before 3.5.11, from 3.4 before 3.4.15.
This CVE is similar but not equivalent to CVE-2026-22733, as the conditions for exploit and vulnerable versions are different.
A flaw was found in Spring Boot. This vulnerability, an authentication bypass, occurs when an application endpoint requiring authentication is declared under a specific path already configured for a Health Group additional p
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-22731 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.2
CVE-2026-22731 [HIGH] CVE-2026-22731 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22731 :
Wolfi vulnerability analysis and mitigation
Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a specific path, already configured for a Health Group additional path.
This issue affects Spring Boot: from 4.0 before 4.0.3, from 3.5 before 3.5.11, from 3.4 before 3.4.15.
This CVE is similar but not equivalent to CVE-2026-22733, as the conditions for exploit and vulnerable versions are different.
Source : NVD
## 8.2
Score
Published March 19, 2026
Severity HIGH
CNA Score 8.2
Affected Technologies
Wolfi
Chainguard
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Pe
Bugzilla
CVE-2026-22731 log4j: Spring Boot: Authentication bypass via misconfigured Health Group additional path [fedora-42]
bugzilla·2026-03-20·CVSS 8.2
CVE-2026-22731 [HIGH] CVE-2026-22731 log4j: Spring Boot: Authentication bypass via misconfigured Health Group additional path [fedora-42]
CVE-2026-22731 log4j: Spring Boot: Authentication bypass via misconfigured Health Group additional path [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently m
Bugzilla
CVE-2026-22731 Spring Boot: Spring Boot: Authentication bypass via misconfigured Health Group additional path
bugzilla·2026-03-19·CVSS 8.2
CVE-2026-22731 [HIGH] CVE-2026-22731 Spring Boot: Spring Boot: Authentication bypass via misconfigured Health Group additional path
CVE-2026-22731 Spring Boot: Spring Boot: Authentication bypass via misconfigured Health Group additional path
Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a specific path, already configured for a Health Group additional path.
This issue affects Spring Boot: from 4.0 before 4.0.3, from 3.5 before 3.5.11, from 3.4 before 3.4.15.
This CVE is similar but not equivalent to CVE-2026-22733, as the conditions for exploit and vulnerable versions are different.
Discussion:
This issue has been addressed in the following products:
Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14
Via RHSA-2026:17668 https://access.redhat.com/errata/RHSA-2026:17668
2026-03-19
Published