Remote JMX RCE in Spring Tools Eclipse <=5.2.0 & VSCode <=2.2.0 via Live Mode
CVE-2026-47858 Published on July 30, 2026
live information startup mode is vulnerable for remote code execution
Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution.
Affected Spring Products and Versions:
Spring Tools for Eclipse: 5.2.0 and earlier
Spring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier
Vulnerability Analysis
Attack Vector:
ADJACENT_NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
REQUIRED
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
Products Associated with CVE-2026-47858
Want to know whenever a new CVE is published for VMware Spring Framework? stack.watch will email you.
Affected Versions
Spring Tools for Eclipse:- Before and including 5.2.0 is affected.
- Before and including 2.2.0 is affected.