Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution.
Affected Spring Products and Versions:
Spring Tools for Eclipse: 5.2.0 and earlier
Spring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier
References
| Link | Resource |
|---|---|
| https://spring.io/security/cve-2026-47858 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-07-30 06:25
Updated : 2026-09-08 20:06
NVD link : CVE-2026-47858
Mitre link : CVE-2026-47858
CVE.ORG link : CVE-2026-47858
JSON object : View
Products Affected
broadcom
- spring_tools
CWE
CWE-306
Missing Authentication for Critical Function
