CVE-2026-47837
Analyzed Analyzed - Analysis Complete

Missing Authentication in Spring Cloud Config Webhook

Vulnerability report for CVE-2026-47837, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-26

Last updated on: 2026-09-04

Assigner: VMware

Description

Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /monitor endpoint are not validated. This issue affects Spring Cloud Config: from 5.0.0 through 5.0.4, from 4.3.0 through 4.3.4, from 4.0.0 through 4.2.8, and through 3.1.14.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-26
Last Modified
2026-09-04
Generated
2026-09-17
AI Q&A
2026-08-26
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
vmware spring_cloud_config From 5.0.0 (inc) to 5.0.5 (exc)
vmware spring_cloud_config to 3.1.15 (exc)
vmware spring_cloud_config From 4.0.0 (inc) to 4.2.9 (exc)
vmware spring_cloud_config From 4.3.0 (inc) to 4.3.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Missing Authentication for Critical Function issue in Spring Cloud Config. It allows unauthenticated webhook requests to the /monitor endpoint of the Spring Cloud Config Server without proper validation. This affects multiple versions of Spring Cloud Config from 3.1.14 and earlier up to 5.0.4.

Detection Guidance

Check if your Spring Cloud Config Server has the /monitor endpoint exposed and verify if webhook requests are reaching it without authentication. Inspect server logs for unusual requests to /monitor. Use network monitoring tools to detect unauthenticated POST requests to this endpoint.

Impact Analysis

An attacker could exploit this to send unauthorized requests to the /monitor endpoint, potentially leading to denial of service or unintended configuration changes. The CVSS score of 6.8 indicates a medium severity with network access required but no privileges needed.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized access to sensitive configuration data through unvalidated webhook requests. Unauthorized changes to configurations may lead to data exposure or integrity issues, violating confidentiality and security requirements under these regulations.

Mitigation Strategies

Upgrade to fixed versions: 5.0.5 (OSS), 4.3.5 (Enterprise), 4.2.9 (Enterprise), or 3.1.15 (Enterprise). No additional mitigation steps are required beyond upgrading.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47837. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart