CVE-2026-47837: VMware Spring Cloud Config
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /monitor endpoint are not validated. This issue affects Spring Cloud Config: from 5.0.0 through 5.0.4, from 4.3.0 through 4.3.4, from 4.0.0 through 4.2.8, and through 3.1.14.
Affected products
- VMware Spring Cloud Config: before 3.1.15 (fixed in 3.1.15); from 4.0.0, before 4.2.9 (fixed in 4.2.9); from 4.3.0, before 4.3.5 (fixed in 4.3.5); from 5.0.0, before 5.0.5 (fixed in 5.0.5)
Published 2026-08-26. Last modified 2026-09-04.