PT-2026-66364 · Vmware · Spring Tools For Cursor+4

CVE-2026-47858

·

Published

2026-07-30

·

Updated

2026-08-01

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Spring Tools for Eclipse versions prior to 5.2.1 Spring Tools for VSCode / Cursor / Theia versions prior to 2.2.1
Description Starting Spring Boot applications in Spring Tools with the live information mode enabled allows for remote code execution via JMX (Java Management Extensions), a technology used for managing and monitoring Java applications.
Recommendations Update Spring Tools for Eclipse to version 5.2.1 or later. Update Spring Tools for VSCode / Cursor / Theia to version 2.2.1 or later. Disable the live information mode when starting Spring Boot applications as a temporary mitigation measure.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47858

Affected Products

Spring Boot
Spring Tools For Cursor
Spring Tools For Eclipse
Spring Tools For Theia
Spring Tools For Vscode