CVE Vulnerabilities

CVE-2026-22731

Authentication Bypass Using an Alternate Path or Channel

Published: Mar 19, 2026 | Modified: Apr 16, 2026
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
8.2 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

Spring Boot applications with Actuator can be vulnerable to an Authentication Bypass vulnerability when an application endpoint that requires authentication is declared under a specific path, already configured for a Health Group additional path. This issue affects Spring Boot: from 4.0 before 4.0.3, from 3.5 before 3.5.11, from 3.4 before 3.4.15. This CVE is similar but not equivalent to CVE-2026-22733, as the conditions for exploit and vulnerable versions are different.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

NameVendorStart VersionEnd Version
Spring_bootVmware3.4.0 (including)3.4.15 (excluding)
Spring_bootVmware3.5.0 (including)3.5.12 (excluding)
Spring_bootVmware4.0.0 (including)4.0.4 (excluding)
HawtIO HawtIO 4.4.0RedHatspring-boot*
Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14RedHatspring-boot*
Red Hat OpenShift Dev Spaces 3.27RedHatdevspaces/openvsx-rhel9:1776716842*
Red Hat OpenShift Dev Spaces 3.27RedHatdevspaces/pluginregistry-rhel9:1776717247*

Potential Mitigations

References