CVE-2026-47858

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
30/07/2026
Last modified:
01/08/2026

Description

Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution.<br /> Affected Spring Products and Versions:<br /> Spring Tools for Eclipse: 5.2.0 and earlier<br /> Spring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier

References to Advisories, Solutions, and Tools