Remote JMX RCE in Spring Tools Eclipse <=5.2.0 & VSCode <=2.2.0 via Live Mode
CVE-2026-47858 Published on July 30, 2026
live information startup mode is vulnerable for remote code execution
Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution.
Affected Spring Products and Versions:
Spring Tools for Eclipse: 5.2.0 and earlier
Spring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier
Vulnerability Analysis
Weakness Type
Missing Authentication for Critical Function
The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Products Associated with CVE-2026-47858
Want to know whenever a new CVE is published for VMware Spring Framework? stack.watch will email you.
Affected Versions
Spring Tools for Eclipse:- Before and including 5.2.0 is affected.
- Before and including 2.2.0 is affected.