Container Control Port Exposure in Spring Tools for Eclipse
CVE-2026-47873

8HIGH

Key Information:

Vendor

Spring

Vendor
CVE Published:
30 July 2026

What is CVE-2026-47873?

The Boot Dashboard integration within Spring Tools for Eclipse allows container control ports to be accessed across all network interfaces (0.0.0.0). This misconfiguration can lead to unauthorized access, potentially exposing sensitive operations and data to threat actors. Users should ensure version 5.2.0 or earlier is updated to mitigate the risks associated with this exposure.

Affected Version(s)

Spring Tools for Eclipse 0 <= 5.2.0

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.