Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution.
Affected Spring Products and Versions:
Spring Tools for Eclipse: 5.2.0 and earlier
Spring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier
References
| Link | Resource |
|---|---|
| https://spring.io/security/cve-2026-47858 |
Configurations
No configuration.
History
30 Jul 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-306 |
30 Jul 2026, 06:25
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-30 06:25
Updated : 2026-08-01 05:16
NVD link : CVE-2026-47858
Mitre link : CVE-2026-47858
CVE.ORG link : CVE-2026-47858
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
