CVE-2026-82265: Zipkin Unauthenticated Spring Boot Actuator Endpoints Exposure

Published Aug 28, 2026
·
Updated

Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tracing API port without authentication, allowing unauthenticated attackers to access sensitive information. Attackers can read environment variables, bean configurations, and storage credentials via actuator endpoints, or modify log levels to suppress logging.

Affected Software

1 affected component
Zipkin<=3.6.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Zipkin to a version that resolves this vulnerability.

    Fixed in 3.6.1
  2. Configuration

    Enable/require authentication for Spring Boot Actuator endpoints exposed on the tracing API port to prevent unauthenticated access to environment variables, bean configurations, and storage credentials

    Spring Boot Actuator (Zipkin) Authentication for Actuator endpoints = required
  3. Configuration

    Prevent attackers from modifying log levels via exposed endpoints so logging cannot be suppressed

    Logging (Zipkin / Spring Boot) Actuator/logging level modification = disable or restrict
  4. Compensating control

    Restrict access to the tracing API port / Spring Boot Actuator endpoints so they are not reachable without authentication (e.g., enforce network/firewall/ingress controls for actuator endpoints)

Event History

Aug 28, 2026
CVE Published
via MITRE·04:18 PM
Data Sourced
via MITRE·04:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which Zipkin versions are potentially affected?

Zipkin versions through 3.6.1 are affected according to the available information.

2

What can an unauthenticated attacker access or change?

An attacker can use Actuator endpoints on the tracing API port to read environment variables, bean configurations, and storage credentials. They can also modify log levels, potentially suppressing logging.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203