References https://github.com/halo-dev/halo/issues/498 https://www.wiz.io/blog/spring-boot-actuator-misconfigurations https://www.invicti.com/web-vulnerability-scanner/vulnerabilities/spring-boot-misconfiguration-actuator-endpoint-security-disabled https://cametom006.medium.com/how-i-found-and-bypassed-a-spring-boot-actuator-information-disclosure-bug-c4930b740a50 https://docs.spring.io/spring-boot/reference/actuator/endpoints.html https://github.com/chaitin/xray/issues/35 https://arxiv.org/pdf/2411.01236 https://www.baeldung.com/spring-boot-actuators https://medium.com/@SecureWithMohit/securing-spring-boot-actuator-identification-and-mitigation-of-vulnerabilities-a8254302f3ac
Related VulnerabilitiesPoCCVE-2026-10818: WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File UploadPoCCVE-2026-26216: Crawl4AI < 0.8.0 - Unauthenticated Remote Code Execution via Hooks ParameterPoCCVE-2026-29058: WWBN AVideo Encoder < 7.0 - Unauthenticated OS Command InjectionPoCCVE-2026-86242: Bifrost < 1.6.3 - Unauthenticated Remote Plugin URL FetchPoCCVE-2026-12227: Visual Composer <= 45.16.0 - Unauthenticated LFIPoCCVE-2026-61560: GitLab MCP Server < 2.1.27 - Unauthenticated SSE Transport AccessPoCCVE-2026-89063: Bookly <=28.1 - IDOR Unauthenticated Sensitive Data AccessPoCmcp-streamable-http-exposure: MCP Streamable HTTP Server - Unauthenticated InitializePoCCVE-2026-6639: AI Copilot Content Generator <=1.4.6 - Unauthenticated Task Data ExposurePoCCVE-2026-80099: Newfold WordPress Plugins - Unauthenticated Admin Bypass via Empty HMAC SecretPoCpowerdns-monitor-exposure: PowerDNS Authoritative Server Monitor - Unauthenticated ExposurePoCCVE-2026-82456: argocd-mcp 0.8.0 - Unauthenticated MCP Session and Tool AccessPoCCVE-2026-84434: WordPress Gravity Forms Plugin <=3.1.0.4 - Unauthenticated Arbitrary File Upload