Code Execution Risk in Spring Boot DevTools for Eclipse by Spring
CVE-2026-59327

4.4MEDIUM

Key Information:

Vendor

Spring

Vendor
CVE Published:
30 July 2026

What is CVE-2026-59327?

The Spring Tools for Eclipse exposes a vulnerability where sensitive remote secrets are stored as plain strings in the launch configuration. This results in cleartext storage in XML format within the workspace or project tree. The exposed secret protects the remote restart and reload endpoint, which can execute arbitrary code on associated Spring Boot applications. This flaw enables attackers who have access to the configuration files to extract and misuse these secrets, leading to potential remote code execution risks.

Affected Version(s)

Spring Tools for Eclipse 0 <= 5.2.0

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.