CVE-2026-50201 Details
Description
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management.Endpoint prior to version 4.2.0 and Steeltoe.Management.EndpointCore prior to version 3.4.0, all Steeltoe actuator endpoints default to `EndpointPermissions.Restricted`, which is mappeds to Cloud Foundry's `read_basic_data` permission (granted to Space Auditors and similar low-trust roles). Sensitive actuators including heap dump, environment, and thread dump do not raise this to `EndpointPermissions.Full`, so CF's `read_sensitive_data` permission flag is not enforced for those endpoints. Spring Boot's equivalent Cloud Foundry integration gates these endpoints with `read_sensitive_data` by default. Steeltoe.Management.Endpoint 4.2.0 and Steeltoe.Management.EndpointCore 3.4.0 patch the issue. If an immediate upgrade is not possible, explicitly set `RequiredPermissions = EndpointPermissions.Full` in the options for `HeapDumpEndpointOptions`, `EnvironmentEndpointOptions`, and `ThreadDumpEndpointOptions`; and/or if heap dump, thread dump, or environment are not needed in production, register only the required actuators individually instead of using `AddAllActuators()`.
A vulnerability exists in Steeltoe.Management.Endpoint versions prior to 4.2.0 and Steeltoe.Management.EndpointBase versions prior to 3.4.0, where sensitive actuator endpoints default to 'EndpointPermissions.Restricted'. This permission level, granted to low-trust roles such as Space Auditors, does not adequately protect sensitive data. Actuators like heap dump, environment, and thread dump fail to require 'EndpointPermissions.Full', allowing unauthorized access to sensitive information. In contrast, Spring Boot's equivalent integration properly restricts access by default.
Users can upgrade to Steeltoe.Management.Endpoint version 4.2.0 or Steeltoe.Management.EndpointBase version 3.4.0 to address this vulnerability. If an immediate upgrade is not possible, 'RequiredPermissions' can be manually set to 'EndpointPermissions.Full' for the affected endpoints. Alternatively, if these actuators are not needed in production, they can be registered individually instead of using 'AddAllActuators()'.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 17, 2026CISA-ADP
Assessed Jun 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | [email protected] |
| CWE-285 | Improper Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Steeltoe.Management.Endpoint | <= 4.1.0 (semver) |
CPE
Remediation
| |
| Steeltoe.Management.EndpointBase | <= 3.3.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 18, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | New CVE Received | [email protected] |
Volerion