VYPR
Unrated severityNVD Advisory· Published Jul 13, 2026· Updated Jul 15, 2026

Spring Boot Admin Server < 4.1.2 SSRF via Unauthenticated Instance Registration

CVE-2026-62242

Description

Spring Boot Admin Server before 4.1.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers to register instances with attacker-controlled healthUrl and managementUrl parameters without validation against private IP ranges or metadata endpoints. Attackers can force the server to make HTTP requests to arbitrary internal addresses and retrieve response bodies via the actuator proxy to exfiltrate cloud credentials.

Affected products

1

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.