CVE-2026-22733: Authentication Bypass under Actuator CloudFoundry endpoints

Published Mar 19, 2026
·
Updated

Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under the path used by the CloudFoundry Actuator endpoints. This issue affects Spring Security: from 4.0.0 through 4.0.3, from 3.5.0 through 3.5.11, from 3.4.0 through 3.4.14, from 3.3.0 through 3.3.17, from 2.7.0 through 2.7.31.

Affected Software

6 affected componentsFixes available
maven/org.springframework.security/spring-security>=4.0.0<=4.0.3, >=3.5.0<=3.5.11, >=3.4.0<=3.4.14, >=3.3.0<=3.3.17, >=2.7.0<=2.7.31
maven/org.springframework.boot:spring-boot-starter-actuator<=2.7.18
maven/org.springframework.boot:spring-boot-starter-actuator>=3.0.0<=3.3.13
maven/org.springframework.boot:spring-boot-starter-actuator>=3.4.0<=3.4.13
maven/org.springframework.boot:spring-boot-starter-actuator>=3.5.0<3.5.12
3.5.12
maven/org.springframework.boot:spring-boot-starter-actuator>=4.0.0-M1<4.0.4
4.0.4

Event History

Mar 19, 2026
CVE Published
via MITRE·11:29 PM
Data Sourced
via MITRE·11:29 PM
DescriptionSeverityWeakness
Mar 20, 2026
Data Sourced
via NVD·12:16 AM
DescriptionSeverityWeakness
Advisory Published
via GitHub·12:31 AM
Data Sourced
via GitHub·12:31 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-22733?

The severity of CVE-2026-22733 is considered high due to the potential for unauthorized access to sensitive application endpoints.

2

How do I fix CVE-2026-22733?

To fix CVE-2026-22733, ensure that authentication is properly enforced on all Actuator endpoints by updating your Spring Security configuration.

3

Which versions are affected by CVE-2026-22733?

CVE-2026-22733 affects Spring Security versions between 2.7.0 to 2.7.31, 3.3.0 to 3.3.17, 3.4.0 to 3.4.14, 3.5.0 to 3.5.11, and 4.0.0 to 4.0.3.

4

Is CVE-2026-22733 applicable to Spring Boot applications?

Yes, CVE-2026-22733 is specifically applicable to Spring Boot applications that utilize Actuator endpoints.

5

What type of vulnerability is CVE-2026-22733?

CVE-2026-22733 is classified as an authentication bypass vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203