8

CVE-2026-47858

live information startup mode is vulnerable for remote code execution

Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution.
Affected Spring Products and Versions:
Spring Tools for Eclipse: 5.2.0 and earlier
Spring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Broadcom ≫ Spring Tools SwPlatform cursor Version < 2.3.0
Broadcom ≫ Spring Tools SwPlatform theia Version < 2.3.0
Broadcom ≫ Spring Tools SwPlatform visual_studio_code Version < 2.3.0
Broadcom ≫ Spring Tools SwPlatform eclipse Version < 5.3.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.097
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
VMware 8 2.1 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.