CVE-2026-62242

Spring Boot Admin Server before 4.1.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers to register instances with attacker-controlled healthUrl and managementUrl parameters without validation against private IP ranges or metadata endpoints. Attackers can force the server to make HTTP requests to arbitrary internal addresses and retrieve response bodies via the actuator proxy to exfiltrate cloud credentials.
Configurations

No configuration.

History

15 Jul 2026, 15:16

Type Values Removed Values Added
References () https://github.com/codecentric/spring-boot-admin/issues/5452 - () https://github.com/codecentric/spring-boot-admin/issues/5452 -

13 Jul 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-13 22:16

Updated : 2026-07-15 21:02


NVD link : CVE-2026-62242

Mitre link : CVE-2026-62242

CVE.ORG link : CVE-2026-62242


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)