Detects Spring Boot applications with CloudFoundry actuator support where the SecurityFilterChain only matches known actuator endpoint paths. Unknown sub-paths under /cloudfoundryapplication/ bypass Spring Security entirely, allowing unauthenticated access to application controllers. Affects Spring Boot 4.0.0–4.0.3, 3.5.0–3.5.11, 3.4.0–3.4.14, 3.3.0–3.3.17, 2.7.0–2.7.31. Update to 3.5.12 or 4.0.4.
Is your app exploitable through CVE-2026-22733?
Scan your domain free