The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0) rather than restricting them to loopback. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-47873 is a configuration vulnerability in Spring Tools for Eclipse versions 5.2.0 and earlier, where the Boot Dashboard Docker integration exposes container control ports to all network interfaces (0.0.0.0) instead of restricting access to loopback (127.0.0.1). This creates a critical security gap for development environments, particularly those connected to shared networks or cloud infrastructure. Attackers on the same network segment can directly access Docker daemon APIs without authentication, enabling container manipulation, escape attempts, and lateral movement. Development teams using Spring Tools for containerized application testing are directly affected, and the risk compounds in corporate networks or CI/CD environments where multiple developers share infrastructure.
While this CVE does not map to specific MITRE ATT&CK techniques, the underlying attack pattern falls within lateral movement and privilege escalation domains. Casky's platform would detect suspicious Docker API interactions by analyzing network communication patterns, unauthorized container lifecycle commands, and anomalous API access attempts. Practitioners would observe findings related to unintended network exposure, insecure service configuration, and potential infrastructure as code misconfigurations. The 0 matching Casky skills reflects the absence of active exploitation signatures, but practitioners should leverage Casky's extensible framework to map this vulnerability to T1021 (Remote Service Session Initiation) and T1566 (Phishing) if weaponized through supply chain attacks targeting development tool installations.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-47873. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation