When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foundry app) from the Spring Tools Boot Dashboard, Spring Tools generates a shared secret that authenticates DevTools remote-restart uploads to the deployed application. This secret was generated using a non-cryptographic pseudo-random number generator rather than a cryptographically secure source of randomness. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-47882 exposes a critical weakness in Spring Tools for Eclipse 5.2.0, where the shared secret protecting remote DevTools restart uploads is generated using a non-cryptographic pseudo-random number generator instead of a cryptographically secure source. This vulnerability (CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator) allows attackers to predict authentication tokens with computational feasibility, potentially enabling unauthorized remote code execution on deployed applications including Docker containers and Cloud Foundry instances. Any organization using Spring Tools to manage remote Spring Boot applications in containerized or cloud environments faces direct risk of compromise through predictable secret recovery.
While this CVE lacks direct MITRE ATT&CK technique mappings, Casky's platform identifies this vulnerability class through behavioral analysis of credential generation patterns and authentication bypass scenarios. Practitioners using Casky would observe findings related to weak cryptographic implementations, predictable token generation, and potential lateral movement vectors—typically associated with techniques like T1078 (Valid Accounts) and T1555 (Credentials from Password Stores) when attackers exploit predictable secrets to gain legitimate-appearing access. Extended reasoning across Casky's 754 mapped security skills enables detection of the underlying weakness: monitoring for non-standard random sources in authentication flows, analyzing entropy characteristics of generated secrets, and correlating repeated authentication attempts that succeed with mathematically-derived token candidates rather than brute force, revealing the fundamental cryptographic weakness before exploitation occurs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-47882. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation