Skip to content
VMwareCVE-2026-47858

VMware Spring Tools for: remote code execution

High8.0CVE-2026-47858 · Published Jul 30, 2026 · updated Sep 8, 2026

Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier Spring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier

VMware advisory

Affected versions

PackageAffectedFixed in
Spring Tools for Eclipse
Product
<= 5.2.0No fix yet
Spring Tools for VSCode / Cursor / Theia
Product
<= 2.2.0No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-306

More VMware advisories

All VMware
Advisory
VMware ESX contains an insufficient logging vulnerability
Low2.7Jul 30
VMware Cloud Foundation: authentication bypass
Critical9.8Jul 30
VMware Cloud Foundation: path traversal
Critical9.8Jul 30
VMware Cloud Foundation: out-of-bounds write
Critical9.3Jul 30
VMware Cloud Foundation: out-of-bounds read
High7.6Jul 30
VMware Spring Tools for: secrets in logs
Low3.3Jul 30

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.