PT-2026-66364 · Vmware · Spring Tools For Cursor+4
CVE-2026-47858
·
Published
2026-07-30
·
Updated
2026-08-01
CVSS v3.1
8.0
High
| Vector | AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Spring Tools for Eclipse versions prior to 5.2.1
Spring Tools for VSCode / Cursor / Theia versions prior to 2.2.1
Description
Starting Spring Boot applications in Spring Tools with the live information mode enabled allows for remote code execution via JMX (Java Management Extensions), a technology used for managing and monitoring Java applications.
Recommendations
Update Spring Tools for Eclipse to version 5.2.1 or later.
Update Spring Tools for VSCode / Cursor / Theia to version 2.2.1 or later.
Disable the live information mode when starting Spring Boot applications as a temporary mitigation measure.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spring Boot
Spring Tools For Cursor
Spring Tools For Eclipse
Spring Tools For Theia
Spring Tools For Vscode