CVE-2026-47858
Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier Spring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier
- CVSS 3.1
- 8.0 HIGH
- EPSS
- 0.2% (10th percentile)
- Weakness
- CWE-306
- NVD status
- Awaiting Analysis
- Published
- 2026-07-30
CVE-2026-47858 at NVD
1 known exploit for CVE-2026-47858
Proof-of-concept code and exploit modules indexed by Sploitus