CVE-2026-22733
published 2026-03-20CVE-2026-22733: Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication…
PriorityP354high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.36%
28.1th percentile
Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under the path used by the CloudFoundry Actuator endpoints. This issue affects Spring Security: from 4.0.0 through 4.0.3, from 3.5.0 through 3.5.11, from 3.4.0 through 3.4.14, from 3.3.0 through 3.3.17, from 2.7.0 through 2.7.31.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring | spring_boot | >= 3.4 < 3.4.15 | 3.4.15 |
| spring | spring_boot | >= 3.5 < 3.5.11 | 3.5.11 |
| spring | spring_boot | >= 4.0 < 4.0.3 | 4.0.3 |
| spring | spring_security | 2.7.0 – 2.7.31 | — |
| spring | spring_security | 3.3.0 – 3.3.17 | — |
| spring | spring_security | 3.4.0 – 3.4.14 | — |
| spring | spring_security | 3.5.0 – 3.5.11 | — |
| spring | spring_security | 4.0.0 – 4.0.3 | — |
| vmware | spring_boot | < 2.7.32 | 2.7.32 |
| vmware | spring_boot | >= 3.3.0 < 3.3.18 | 3.3.18 |
| vmware | spring_boot | >= 3.4.0 < 3.4.15 | 3.4.15 |
| vmware | spring_boot | >= 3.5.0 < 3.5.12 | 3.5.12 |
| vmware | spring_boot | >= 4.0.0 < 4.0.4 | 4.0.4 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
ghsa8.2HIGH
osv8.2HIGH
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Spring Boot has an Authentication Bypass under Actuator Health groups paths
ghsa·2026-03-20·CVSS 8.2
CVE-2026-22731 [HIGH] CWE-288 Spring Boot has an Authentication Bypass under Actuator Health groups paths
Spring Boot has an Authentication Bypass under Actuator Health groups paths
Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a specific path, already configured for a Health Group additional path.
This issue affects Spring Boot: from 4.0 before 4.0.3, from 3.5 before 3.5.11, from 3.4 before 3.4.15.
This CVE is similar but not equivalent to CVE-2026-22733, as the conditions for exploit and vulnerable versions are different.
GHSA
Spring Boot has an Authentication Bypass under Actuator CloudFoundry endpoints
ghsa·2026-03-20
CVE-2026-22733 [HIGH] CWE-288 Spring Boot has an Authentication Bypass under Actuator CloudFoundry endpoints
Spring Boot has an Authentication Bypass under Actuator CloudFoundry endpoints
Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under the path used by the CloudFoundry Actuator endpoints. This issue affects Spring Security: from 4.0.0 through 4.0.3, from 3.5.0 through 3.5.11, from 3.4.0 through 3.4.14, from 3.3.0 through 3.3.17, from 2.7.0 through 2.7.31.
OSV
Spring Boot has an Authentication Bypass under Actuator Health groups paths
osv·2026-03-20·CVSS 8.2
CVE-2026-22731 [HIGH] Spring Boot has an Authentication Bypass under Actuator Health groups paths
Spring Boot has an Authentication Bypass under Actuator Health groups paths
Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a specific path, already configured for a Health Group additional path.
This issue affects Spring Boot: from 4.0 before 4.0.3, from 3.5 before 3.5.11, from 3.4 before 3.4.15.
This CVE is similar but not equivalent to CVE-2026-22733, as the conditions for exploit and vulnerable versions are different.
OSV
Spring Boot has an Authentication Bypass under Actuator CloudFoundry endpoints
osv·2026-03-20
CVE-2026-22733 [HIGH] Spring Boot has an Authentication Bypass under Actuator CloudFoundry endpoints
Spring Boot has an Authentication Bypass under Actuator CloudFoundry endpoints
Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under the path used by the CloudFoundry Actuator endpoints. This issue affects Spring Security: from 4.0.0 through 4.0.3, from 3.5.0 through 3.5.11, from 3.4.0 through 3.4.14, from 3.3.0 through 3.3.17, from 2.7.0 through 2.7.31.
Red Hat
Spring Boot: Spring Boot: Authentication bypass via misconfigured Health Group additional path
vendor_redhat·2026-03-19·CVSS 8.2
CVE-2026-22731 [HIGH] CWE-305 Spring Boot: Spring Boot: Authentication bypass via misconfigured Health Group additional path
Spring Boot: Spring Boot: Authentication bypass via misconfigured Health Group additional path
Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a specific path, already configured for a Health Group additional path.
This issue affects Spring Boot: from 4.0 before 4.0.3, from 3.5 before 3.5.11, from 3.4 before 3.4.15.
This CVE is similar but not equivalent to CVE-2026-22733, as the conditions for exploit and vulnerable versions are different.
A flaw was found in Spring Boot. This vulnerability, an authentication bypass, occurs when an application endpoint requiring authentication is declared under a specific path already configured for a Health Group additional p
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-22731 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.2
CVE-2026-22731 [HIGH] CVE-2026-22731 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22731 :
Wolfi vulnerability analysis and mitigation
Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a specific path, already configured for a Health Group additional path.
This issue affects Spring Boot: from 4.0 before 4.0.3, from 3.5 before 3.5.11, from 3.4 before 3.4.15.
This CVE is similar but not equivalent to CVE-2026-22733, as the conditions for exploit and vulnerable versions are different.
Source : NVD
## 8.2
Score
Published March 19, 2026
Severity HIGH
CNA Score 8.2
Affected Technologies
Wolfi
Chainguard
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Pe
Wiz
CVE-2026-22733 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.2
CVE-2026-22733 [HIGH] CVE-2026-22733 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22733 :
Wolfi vulnerability analysis and mitigation
Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under the path used by the CloudFoundry Actuator endpoints. This issue affects Spring Security: from 4.0.0 through 4.0.3, from 3.5.0 through 3.5.11, from 3.4.0 through 3.4.14, from 3.3.0 through 3.3.17, from 2.7.0 through 2.7.31.
Source : NVD
## 8.2
Score
Published March 20, 2026
Severity HIGH
CNA Score 8.2
Affected Technologies
Wolfi
Chainguard
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 15.3
Exploitation Probability (EPSS) N/A
Affected packages a
Bugzilla
CVE-2026-22731 Spring Boot: Spring Boot: Authentication bypass via misconfigured Health Group additional path
bugzilla·2026-03-19·CVSS 8.2
CVE-2026-22731 [HIGH] CVE-2026-22731 Spring Boot: Spring Boot: Authentication bypass via misconfigured Health Group additional path
CVE-2026-22731 Spring Boot: Spring Boot: Authentication bypass via misconfigured Health Group additional path
Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a specific path, already configured for a Health Group additional path.
This issue affects Spring Boot: from 4.0 before 4.0.3, from 3.5 before 3.5.11, from 3.4 before 3.4.15.
This CVE is similar but not equivalent to CVE-2026-22733, as the conditions for exploit and vulnerable versions are different.
Discussion:
This issue has been addressed in the following products:
Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14
Via RHSA-2026:17668 https://access.redhat.com/errata/RHSA-2026:17668
2026-03-20
Published