CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.2. See the original NVD description below for full technical details.
CVE
CVE-2026-22733
Severity
HIGH
CVSS
8.2
EPSS
0.36%
Original NVD Description
Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under the path used by the CloudFoundry Actuator endpoints. This issue affects Spring Security: from 4.0.0 through 4.0.3, from 3.5.0 through 3.5.11, from 3.4.0 through 3.4.14, from 3.3.0 through 3.3.17, from 2.7.0 through 2.7.31.
Related CVEs
Other vulnerabilities affecting the same vendor(s)