SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82265

MEDIUM · CVSS 6.5 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Zipkin versions up to 3.6.1 are vulnerable due to the exposure of Spring Boot Actuator endpoints on the tracing API port without authentication, enabling unauthenticated attackers to access sensitive information such as environment variables and storage credentials. The potential impact includes unauthorized data disclosure and the ability to manipulate logging behavior, which could hinder incident detection. Organizations using affected versions of Zipkin should prioritize remediation to protect sensitive data and maintain operational integrity.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82265
Severity
MEDIUM
CVSS
6.5
EPSS
0.32%

Original NVD Description

Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tracing API port without authentication, allowing unauthenticated attackers to access sensitive information. Attackers can read environment variables, bean configurations, and storage credentials via actuator endpoints, or modify log levels to suppress logging.