SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-47837

MEDIUM · CVSS 6.8 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability in Spring Cloud Config allows unauthenticated Webhook requests to the /monitor endpoint, potentially enabling unauthorized access to sensitive configuration data. This issue affects multiple versions of Spring Cloud Config, specifically from 3.1.14 to 5.0.4. Organizations using these versions should prioritize remediation to prevent potential exploitation and protect their configuration management processes.

CVE
CVE-2026-47837
Severity
MEDIUM
CVSS
6.8
EPSS
0.30%

Original NVD Description

Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /monitor endpoint are not validated. This issue affects Spring Cloud Config: from 5.0.0 through 5.0.4, from 4.3.0 through 4.3.4, from 4.0.0 through 4.2.8, and through 3.1.14.

Related CVEs

Other vulnerabilities affecting the same vendor(s)