CVE-2026-47858

Summary

Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier Spring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier

Affected Software

VendorProductVersion RangeStatus
SpringSpring Tools for Eclipse0 <= 5.2.0affected
SpringSpring Tools for VSCode / Cursor / Theia0 <= 2.2.0affected

Weaknesses

  • CWE-306 Missing Authentication for Critical Function

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References