Weakness in Remote Application Authentication for Spring Tools by Pivotal Software
CVE-2026-47882

8.3HIGH

Key Information:

Vendor

Spring

Vendor
CVE Published:
30 July 2026

What is CVE-2026-47882?

The Spring Tools for Eclipse has a vulnerability in the generation of shared secrets used for authenticating DevTools remote-restart uploads. This vulnerability arises when supporting remote application targets, such as those deployed in Docker containers or on Cloud Foundry. The concern lies in the fact that the shared secret is produced using a non-cryptographic pseudo-random number generator instead of a cryptographically secure source. This approach compromises the strength of the secret, potentially allowing unauthorized access to the deployed application through insecure authentication processes.

Affected Version(s)

Spring Tools for Eclipse 0 <= 5.2.0

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.