CVE-2026-59284
Analyzed
Analyzed - Analysis Complete
Spring Cloud Commons Property Key Injection Vulnerability
Vulnerability report for CVE-2026-59284, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-27
Last updated on: 2026-09-01
Assigner: VMware
Description
Description
There is no allow list for property keys when Spring Cloud Commons writable /actuator/env is enabled.
Spring Cloud Commons 5.0.0 - 5.0.2
Spring Cloud Commons 4.3.0 - 4.3.3
Spring Cloud Commons 4.0.0 - 4.2.6
Spring Cloud Commons 3.1.10 and earlier
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| broadcom | spring_cloud_commons | to 3.1.11 (exc) |
| broadcom | spring_cloud_commons | From 4.0.0 (inc) to 4.2.7 (exc) |
| broadcom | spring_cloud_commons | From 4.3.0 (inc) to 4.3.4 (exc) |
| broadcom | spring_cloud_commons | From 5.0.0 (inc) to 5.0.3 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-915 | The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified. |