CVE-2026-59327

Source
https://cve.org/CVERecord?id=CVE-2026-59327
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-59327.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-59327
Published
2026-07-30T05:29:20Z
Modified
2026-10-02T03:47:29Z
Severity
  • 4.4 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Cleartext Storage of Spring Boot DevTools Remote Secret in Eclipse Launch Configurations
Details

Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain string attribute on the "Spring Boot DevTools Client" launch configuration. Eclipse persists launch configuration attributes as cleartext XML, either to workspace metadata or, if the user marks the configuration as a shared file, directly into the project tree where it can be committed to version control. This secret is the sole credential protecting the DevTools remote restart/reload endpoint, which accepts and executes arbitrary class bytes on the target application. Anyone able to read the .launch file (via filesystem access, a workspace backup, or a shared VCS repository) can extract the secret and use it to achieve remote code execution against the associated Spring Boot application. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier

Database specific
{
    "cna_assigner": "vmware",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59327.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "last_affected": "5.2.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/spring-projects/spring-tools

Affected ranges

Type
GIT
Repo
https://github.com/spring-projects/spring-tools
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:broadcom:spring_tools:*:*:*:*:*:eclipse:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "5.3.0"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

3.*
3.9.15.RELEASE
3.9.7.RELEASE
4.*
4.0.0.RELEASE
4.0.1.RELEASE
4.0.2.RELEASE
4.1.1.RELEASE
4.1.2.RELEASE
4.10.0.RELEASE
4.11.0.RELEASE
4.11.1.RELEASE
4.12.0.RELEASE
4.12.1.RELEASE
4.13.0.RELEASE
4.13.1.RELEASE
4.14.0.RELEASE
4.14.1.RELEASE
4.15.0.RELEASE
4.15.2.RELEASE
4.15.3.RELEASE
4.16.0.RELEASE
4.16.1.RELEASE
4.17.0.RELEASE
4.17.1.RELEASE
4.17.2.RELEASE
4.18.0.RELEASE
4.18.1.RELEASE
4.19.0.RELEASE
4.2.0.RELEASE
4.2.1.RELEASE
4.2.2.RELEASE
4.20.0.RELEASE
4.20.1.RELEASE
4.21.0.RELEASE
4.21.1.RELEASE
4.22.0.RELEASE
4.22.1.RELEASE
4.23.0.RELEASE
4.24.0.RELEASE
4.25.0.RELEASE
4.26.0.RELEASE
4.27.0.RELEASE
4.28.0.RELEASE
4.29.0.RELEASE
4.3.0.RELEASE
4.3.1.RELEASE
4.3.2.RELEASE
4.30.0.RELEASE
4.31.0.RELEASE
4.4.1.RELEASE
4.4.2.RELEASE
4.5.0.RELEASE
4.5.1.RELEASE
4.6.0.RELEASE
4.6.1.RELEASE
4.6.2.RELEASE
4.7.0.RELEASE
4.7.1.RELEASE
4.7.2.RELEASE
4.8.0.RELEASE
4.8.1.RELEASE
4.9.0.RELEASE
5.*
5.0.0.RC1
5.0.0.RC2
5.0.0.RELEASE
5.1.0.RELEASE
5.2.0.RELEASE
CF-Manifest-LS-STS-3.*
CF-Manifest-LS-STS-3.9.0.RELEASE
Other
REPO-REORG
REPO-REORG-2020
V_0.*
V_0.0.4-RC.1
V_0.0.5
V_0.0.5-RC.1
V_0.0.5-RC.2
V_0.0.5-RC.3
V_0.0.5-RC.4
V_0.0.5-RC.5
V_0.0.5-RC.6
V_0.0.5-RC.7
V_0.0.6
V_0.0.6-RC.1
V_0.0.7
V_0.0.7-RC.1
V_0.0.8
V_0.0.8-RC.1
V_0.0.9
V_0.0.9-RC.2
V_0.0.9-RC.3
V_0.0.9-RC.4
V_0.1.0
V_0.1.0-RC.1
V_0.1.2
V_0.1.2-RC.1
V_0.1.2-RC.2
V_0.1.2-RC.3
V_0.1.3
V_0.1.3-RC.1
V_0.1.4
V_0.1.4-RC.1
V_0.2.1
V_0.2.1-RC.1
V_0.3.0
V_0.3.0-RC.1
V_0.3.1
V_0.3.1-RC.1
V_0.3.2-RC.1
V_0.4.0
V_0.4.0-RC.1
V_0.5.0
V_0.5.0-RC.1
V_0.5.0-RC.2
V_0.5.0-RC.3
V_0.6.0
V_0.6.0-RC.1
V_0.6.0-RC.2
V_0.6.0-RC.3
V_0.7.0-RC.1
V_1.*
V_1.0.0
V_1.0.0-RC.1
V_1.0.0-RC.2
V_1.0.0-RC.3
V_1.0.0-RC.4
V_1.0.0-RC.5
V_1.0.0-RC.6
V_1.1.0
V_1.1.0-RC.1
V_1.1.0-RC.3
V_1.1.0-RC.4
V_1.1.1
V_1.1.1-RC.1
V_1.1.1-RC.2
V_1.1.1-RC.3
V_1.10.0
V_1.10.0-RC.1
V_1.12.0
V_1.12.0-RC.1
V_1.12.0-RC.2
V_1.12.0-RC.3
V_1.12.0-RC.4
V_1.13.0
V_1.13.0-RC.1
V_1.14.0
V_1.14.0-RC.1
V_1.15.0
V_1.15.0-RC.1
V_1.16.0-RC.1
V_1.16.0-RC.2
V_1.17.0
V_1.17.0-RC.1
V_1.18.0
V_1.18.0-RC.1
V_1.2.0
V_1.2.0-RC.1
V_1.20.0
V_1.20.0-RC.1
V_1.21.0
V_1.21.0-RC.1
V_1.21.0-RC.2
V_1.22.0
V_1.22.0-RC.1
V_1.23.0
V_1.23.0-RC.1
V_1.23.0-RC.2
V_1.24.0
V_1.24.0-RC.1
V_1.25.0
V_1.25.0-RC.1
V_1.25.0-RC.2
V_1.25.1
V_1.25.1-RC.1
V_1.25.1-RC.2
V_1.26.0-RC.2
V_1.27.0
V_1.27.0-RC.1
V_1.28.0
V_1.28.0-RC.1
V_1.29.0
V_1.29.0-RC.1
V_1.29.0-RC.2
V_1.3.0
V_1.3.0-RC.1
V_1.30.0
V_1.30.0-RC.1
V_1.31.0
V_1.31.0-RC.1
V_1.31.0-RC.2
V_1.32.0
V_1.32.0-RC.1
V_1.32.0-RC.2
V_1.33.0
V_1.33.0-RC.2
V_1.34.0
V_1.34.0-RC.1
V_1.35.0
V_1.35.0-RC.1
V_1.36.0-RC.1
V_1.37.0
V_1.37.0-RC.1
V_1.37.0-RC.2
V_1.38.0
V_1.38.0-RC.1
V_1.38.0-RC.3
V_1.39.0
V_1.39.0-RC.1
V_1.4.0
V_1.4.0-RC.1
V_1.40.0
V_1.40.0-RC.1
V_1.41.0
V_1.41.0-RC.1
V_1.41.0-RC.2
V_1.42.0
V_1.42.0-RC.1
V_1.42.0-RC.2
V_1.42.0-RC.3
V_1.42.0-RC.4
V_1.43.0
V_1.43.0-RC.1
V_1.44.0
V_1.44.0-RC.1
V_1.44.0-RC.2
V_1.45.0
V_1.45.0-RC.1
V_1.45.0-RC.2
V_1.45.0-RC.3
V_1.46.0-RC.1
V_1.46.0-RC.2
V_1.47.0
V_1.47.0-RC.1
V_1.49.0
V_1.49.0-RC.1
V_1.49.0-RC.2
V_1.5.0
V_1.5.0-RC.1
V_1.5.0-RC.2
V_1.5.0-RC.3
V_1.50.0
V_1.50.0-RC.1
V_1.50.0-RC.2
V_1.51.0
V_1.51.0-RC.1
V_1.51.0-RC.2
V_1.51.0-RC.3
V_1.52.0
V_1.52.0-RC.1
V_1.53.0
V_1.53.0-RC.1
V_1.53.0-RC.2
V_1.53.0-RC.3
V_1.54.0
V_1.54.0-RC.1
V_1.54.0-RC.2
V_1.55.0
V_1.55.0-RC.1
V_1.6.0
V_1.6.0-RC.1
V_1.7.0
V_1.7.0-RC.1
V_1.7.0-RC.2
V_1.8.0
V_1.8.0-RC.1
V_1.9.0
V_1.9.0-RC.1
V_1.9.0-RC.2
v0.*
v0.0.1
v2.*
v2.2.0
vscode-boot-dev-pack-0.*
vscode-boot-dev-pack-0.2.2
vscode-bosh-1.*
vscode-bosh-1.56.0-M1
vscode-concourse-0.*
vscode-concourse-0.0.1-RELEASE
vscode-concourse-1.*
vscode-concourse-1.56.0-RC1
vscode-manifest-yaml-0.*
vscode-manifest-yaml-0.0.1-RC1
vscode-manifest-yaml-0.0.1-RELEASE
vscode-manifest-yaml-0.0.2-RC1
vscode-manifest-yaml-0.0.2-RELEASE
vscode-spring-boot-1.*
vscode-spring-boot-1.56.0-RC1
vscode-spring-boot-1.56.0-RC2
vscode-spring-boot-1.57.0-RC1
vscode-spring-boot-1.57.0-RC2
vscode-spring-boot-1.57.0-RC3
vscode-spring-boot-1.58.0-RC1
vscode-spring-boot-1.59.0-RC1
vscode-spring-boot-1.59.0-RC2
vscode-spring-boot-1.60.0-RC1
vscode-spring-boot-1.60.0-RC2
vscode-spring-boot-1.61.0-RC1
vscode-spring-boot-1.61.0-RC2
vscode-spring-boot-1.62.0-RC1
vscode-spring-boot-1.63.0-RC1
vscode-spring-boot-1.63.0-RC2
vscode-spring-boot-2.*
vscode-spring-boot-2.0.0-RC2
vscode-spring-boot-2.0.0-RC3
vscode-spring-boot-2.1.0-RC1
vscode-spring-boot-2.1.0-RC2
vscode-spring-boot-2.1.0-RC3
vscode-spring-boot-2.2.0-RC1
vscode-spring-boot-2.3.0-RC1
vscode-spring-cli-0.*
vscode-spring-cli-0.9.0-RC1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-59327.json"