๐Ÿ” CVE Alert

CVE-2026-59327

MEDIUM 4.4

Cleartext Storage of Spring Boot DevTools Remote Secret in Eclipse Launch Configurations

CVSS Score
4.4
EPSS Score
0.0%
EPSS Percentile
0th

Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain string attribute on the "Spring Boot DevTools Client" launch configuration. Eclipse persists launch configuration attributes as cleartext XML, either to workspace metadata or, if the user marks the configuration as a shared file, directly into the project tree where it can be committed to version control. This secret is the sole credential protecting the DevTools remote restart/reload endpoint, which accepts and executes arbitrary class bytes on the target application. Anyone able to read the .launch file (via filesystem access, a workspace backup, or a shared VCS repository) can extract the secret and use it to achieve remote code execution against the associated Spring Boot application. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier

Vendor spring
Product spring tools for eclipse
Ecosystems
Industries
TechnologyEnterprise
Published Jul 30, 2026
Last Updated Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for spring spring tools for eclipse

Be the first to know when new medium vulnerabilities affecting spring spring tools for eclipse are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

Spring / Spring Tools for Eclipse
0 โ‰ค 5.2.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
spring.io: https://spring.io/security/cve-2026-59327