« Volver al listado

CVE-2026-47858

Estado: AnalizadaAlta (8)—

Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier Spring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector AV:A UI:R indica ejecución en cliente (abrir herramienta de desarrollo con modo live activado). JMX permite RCE, luego ejecución de código. Acceso de cuenta local posterior (T1078) sin evidencia de escalada explícita.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-47858",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-47858",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-07-31T00:00:00+00:00"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@vmware.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.1
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "Spring",
          "product": "Spring Tools for Eclipse",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "5.2.0"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Spring",
          "product": "Spring Tools for VSCode / Cursor / Theia",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "2.2.0"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-07-30T06:25:52.120",
  "references": [
    {
      "url": "https://spring.io/security/cve-2026-47858",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@vmware.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-306"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution.\nAffected Spring Products and Versions:\nSpring Tools for Eclipse: 5.2.0 and earlier\nSpring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier"
    }
  ],
  "lastModified": "2026-09-08T20:06:31.953",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:broadcom:spring_tools:*:*:*:*:*:cursor:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CAEC8CA5-9BAA-4793-B1D8-F3FB0ED114A7",
              "versionEndExcluding": "2.3.0"
            },
            {
              "criteria": "cpe:2.3:a:broadcom:spring_tools:*:*:*:*:*:theia:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9D4854E4-13A4-4099-88D4-4117B7FB598D",
              "versionEndExcluding": "2.3.0"
            },
            {
              "criteria": "cpe:2.3:a:broadcom:spring_tools:*:*:*:*:*:visual_studio_code:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1D0B41C8-7DAA-4769-87D5-23AA3D92B314",
              "versionEndExcluding": "2.3.0"
            },
            {
              "criteria": "cpe:2.3:a:broadcom:spring_tools:*:*:*:*:*:eclipse:*:*",
              "vulnerable": true,
              "matchCriteriaId": "32B3B8F5-9BB0-496A-87C0-161B75ABE2F0",
              "versionEndExcluding": "5.3.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@vmware.com"
}