CVE-2026-22731 | VMware Spring Boot up to 3.4.14/3.5.10/4.0.2 Actuator Health Group authentication bypass (WID-SEC-2026-0799)
A vulnerability, which was classified as critical, was found in VMware Spring Boot up to 3.4.14/3.5.10/4.0.2. The impacted element is an unknown function of the component Actuator Health Group Handler. The manipulation results in authentication bypass using alternate channel.
This vulnerability is cataloged as CVE-2026-22731. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.