CVE-2026-47858 Details
Description
Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier Spring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier
A remote code execution vulnerability has been identified in Spring Tools for Eclipse versions through 5.2.0 and in Spring Tools for Visual Studio Code, Cursor, and Theia versions through 2.2.0. The vulnerability arises when Spring Boot applications are started with the live information mode enabled, exposing them to JMX-based remote code execution.
Users should upgrade to Spring Tools for Eclipse 5.3.0 or Spring Tools for VSCode/Cursor/Theia 2.3.0. For unpatched versions, disable the live information mode when starting Spring Boot applications from the IDE.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://spring.io/security/cve-2026-47858 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| broadcom spring tools | < 2.3.0 < 5.3.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 8, 2026 | Initial Analysis | [email protected] |
| Aug 1, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2026 | New CVE Received | [email protected] |