Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-22731

Опубликовано: 19 мар. 2026
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a specific path, already configured for a Health Group additional path. This issue affects Spring Boot: from 4.0 before 4.0.3, from 3.5 before 3.5.11, from 3.4 before 3.4.15. This CVE is similar but not equivalent to CVE-2026-22733, as the conditions for exploit and vulnerable versions are different.

A flaw was found in Spring Boot. This vulnerability, an authentication bypass, occurs when an application endpoint requiring authentication is declared under a specific path already configured for a Health Group additional path. A remote attacker could exploit this to bypass authentication, potentially gaining unauthorized access to sensitive application endpoints. This could lead to information disclosure or unauthorized actions.

Меры по смягчению последствий

To mitigate, ensure that application endpoints requiring authentication are not declared under paths already configured as Health Group additional paths within Spring Boot applications using Actuator. Review and adjust your application's configuration to prevent this overlap. A redeployment of the application is required for changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Broker 7spring-bootNot affected
Red Hat AMQ Clientsspring-bootAffected
Red Hat build of OptaPlanner 8spring-bootWill not fix
Red Hat Data Grid 8spring-bootWill not fix
Red Hat Fuse 7spring-bootWill not fix
Red Hat JBoss Enterprise Application Platform 7spring-bootNot affected
Red Hat JBoss Enterprise Application Platform 8spring-bootNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packspring-bootAffected
Red Hat Process Automation 7spring-bootNot affected
Red Hat Single Sign-On 7spring-bootWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-305
https://bugzilla.redhat.com/show_bug.cgi?id=2449290Spring Boot: Spring Boot: Authentication bypass via misconfigured Health Group additional path

EPSS

Процентиль: 26%
0.00334
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
nvd
5 месяцев назад

Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a specific path, already configured for a Health Group additional path. This issue affects Spring Boot: from 4.0 before 4.0.3, from 3.5 before 3.5.11, from 3.4 before 3.4.15. This CVE is similar but not equivalent to CVE-2026-22733, as the conditions for exploit and vulnerable versions are different.

CVSS3: 8.2
github
5 месяцев назад

Spring Boot has an Authentication Bypass under Actuator Health groups paths

EPSS

Процентиль: 26%
0.00334
Низкий

8.2 High

CVSS3

Уязвимость CVE-2026-22731