CVE-2026-59284: Broadcom Spring Cloud Commons

High severity, CVSS 7.6. EPSS: 0.4% chance of exploitation in the next 30 days.

There is no allow list for property keys when Spring Cloud Commons writable /actuator/env is enabled. Spring Cloud Commons 5.0.0 - 5.0.2 Spring Cloud Commons 4.3.0 - 4.3.3 Spring Cloud Commons 4.0.0 - 4.2.6 Spring Cloud Commons 3.1.10 and earlier

Affected products

  • Broadcom Spring Cloud Commons: before 3.1.11 (fixed in 3.1.11); from 4.0.0, before 4.2.7 (fixed in 4.2.7); from 4.3.0, before 4.3.4 (fixed in 4.3.4); from 5.0.0, before 5.0.3 (fixed in 5.0.3)

Published 2026-08-27. Last modified 2026-09-01.