CVE Explorer
CVE-2026-59327
Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain string attribute on the "Spring Boot DevTools Client" launch configuration. Eclipse persists launch configuration attributes as cleartext XML, either to workspace metadata or, if the user marks the configuration as a shared file, directly into the project tree where it can be committed to version control. This secret is the sole credential protecting the DevTools remote restart/reloa
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-312","description":"CWE-312 Cleartext Storage of Sensitive Information","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:19a82e228df4835c2e903f31d3cb3eda9ec0a22e65e3a3916cad9fbd29507e9d · sha256:d3117a2599a11688… · /containers/adp/0/problemTypes/0/descriptions/0
{"description":"CWE-312 Cleartext Storage of Sensitive Information","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:19a82e228df4835c2e903f31d3cb3eda9ec0a22e65e3a3916cad9fbd29507e9d · sha256:d3117a2599a11688… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Spring Tools for Eclipse","vendor":"Spring","versions":[{"lessThanOrEqual":"5.2.0","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:19a82e228df4835c2e903f31d3cb3eda9ec0a22e65e3a3916cad9fbd29507e9d · sha256:d3117a2599a11688… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":4.4,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:19a82e228df4835c2e903f31d3cb3eda9ec0a22e65e3a3916cad9fbd29507e9d · sha256:d3117a2599a11688… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-312","description":"CWE-312 Cleartext Storage of Sensitive Information","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:19a82e228df4835c2e903f31d3cb3eda9ec0a22e65e3a3916cad9fbd29507e9d · sha256:d3117a2599a11688… · /containers/adp/0/problemTypes/0/descriptions/0
{"description":"CWE-312 Cleartext Storage of Sensitive Information","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:19a82e228df4835c2e903f31d3cb3eda9ec0a22e65e3a3916cad9fbd29507e9d · sha256:d3117a2599a11688… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://spring.io/security/cve-2026-59327"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:19a82e228df4835c2e903f31d3cb3eda9ec0a22e65e3a3916cad9fbd29507e9d · sha256:d3117a2599a11688… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.