Unrated severityNVD Advisory· Published Jul 13, 2026· Updated Jul 15, 2026
Spring Boot Admin Server < 4.1.2 SSRF via Unauthenticated Instance Registration
CVE-2026-62242
Description
Spring Boot Admin Server before 4.1.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers to register instances with attacker-controlled healthUrl and managementUrl parameters without validation against private IP ranges or metadata endpoints. Attackers can force the server to make HTTP requests to arbitrary internal addresses and retrieve response bodies via the actuator proxy to exfiltrate cloud credentials.
Affected products
1- Range: <4.1.2
Patches
Vulnerability mechanics
References
5- github.com/codecentric/spring-boot-admin/commit/1f991ea013e46360b8f8fb63fe4ad20a9bf0d551mitrepatch
- github.com/codecentric/spring-boot-admin/pull/5464mitreissue-trackingpatch
- github.com/codecentric/spring-boot-admin/releases/tag/4.1.2mitrerelease-notespatch
- github.com/codecentric/spring-boot-admin/issues/5452mitretechnical-descriptionexploitissue-tracking
- www.vulncheck.com/advisories/spring-boot-admin-server-ssrf-via-unauthenticated-instance-registrationmitrethird-party-advisory
News mentions
0No linked articles in our index yet.