Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-47837

Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /monitor endpoint are not validated. This issue affects Spring Cloud Config: from 5.0.0 through 5.0.4, from 4.3.0 through 4.3.4, from 4.0.0 through 4.2.8, and through 3.1.14.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 20.5%
CVSS Severity
CVSS v3 Score 6.8


Contact Us

Shodan ® - All rights reserved