CVE-2026-47858
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
30/07/2026
Last modified:
01/08/2026
Description
Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution.<br />
Affected Spring Products and Versions:<br />
Spring Tools for Eclipse: 5.2.0 and earlier<br />
Spring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier
Impact
Base Score 3.x
8.00
Severity 3.x
HIGH



