CVE Vulnerabilities

CVE-2026-22733

Authentication Bypass Using an Alternate Path or Channel

Published: Mar 20, 2026 | Modified: Apr 23, 2026
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Spring Boot applications with Actuator can be vulnerable to an Authentication Bypass vulnerability when an application endpoint that requires authentication is declared under the path used by the CloudFoundry Actuator endpoints. This issue affects Spring Security: from 4.0.0 through 4.0.3, from 3.5.0 through 3.5.11, from 3.4.0 through 3.4.14, from 3.3.0 through 3.3.17, from 2.7.0 through 2.7.31.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

NameVendorStart VersionEnd Version
Spring_bootVmware*2.7.32 (excluding)
Spring_bootVmware3.3.0 (including)3.3.18 (excluding)
Spring_bootVmware3.4.0 (including)3.4.15 (excluding)
Spring_bootVmware3.5.0 (including)3.5.12 (excluding)
Spring_bootVmware4.0.0 (including)4.0.4 (excluding)

Potential Mitigations

References