8
CVE-2026-47858
- EPSS 0.2%
- Veröffentlicht 30.07.2026 05:15:31
- Zuletzt bearbeitet 08.09.2026 20:06:31
- Erkennungen
live information startup mode is vulnerable for remote code execution
Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier Spring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Broadcom ≫ Spring Tools SwPlatform cursor Version < 2.3.0
Broadcom ≫ Spring Tools SwPlatform theia Version < 2.3.0
Broadcom ≫ Spring Tools SwPlatform visual_studio_code Version < 2.3.0
Broadcom ≫ Spring Tools SwPlatform eclipse Version < 5.3.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.097 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| VMware | 8 | 2.1 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
https://spring.io/security/cve-2026-47858