THREAT OPS › Threat News › [NVD] CVE-2026-47858 (HIGH 8.0) — Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution.
Affected Spring Products and Versions:
Spring Tools for Eclipse: 5.2.0 and earlier
Spring Tools for VSCod
[NVD] CVE-2026-47858 (HIGH 8.0) — Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier Spring Tools for VSCod
CVE-2026-47858 CVSS: 8.0 HIGH Published: 2026-07-30T06:25:52.120
Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier Spring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier
Indicators of compromise
- CVE-2026-47858cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-47858