SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-59328

MEDIUM · CVSS 4.2 EPSS 0.17% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The vulnerability affects Spring Tools for Eclipse versions 5.2.0 and earlier, where the embedded SWT Browser can execute arbitrary scripts when developers interact with dependency tooltips in the Spring Boot starter wizard. This can lead to UI spoofing and potential outbound network beaconing, though it does not allow for full code execution. Developers using these versions should prioritize this issue to mitigate risks associated with untrusted Initializr endpoints.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-59328
Severity
MEDIUM
CVSS
4.2
EPSS
0.17%
Java

Original NVD Description

Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browser) with JavaScript enabled. Using untrusted and compromised Initializr endpoints for the Spring Boot starter wizard can result in arbitrary script execution inside the embedded browser when a developer hovers a dependency checkbox in the New Spring Starter Project wizard. Impact is limited to in-IDE UI spoofing and outbound network beaconing rather than full code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier