References https://zhuanlan.zhihu.com/p/602691208 https://blog.csdn.net/weixin_44106034/article/details/133934404 https://apifox.com/apiskills/how-to-use-spring-boot-actuator-2/ https://github.com/rabbitmask/SB-Actuator https://www.wangsu.com/news/content/blog/3741 https://comate.baidu.com/zh/page/ilk8i1rh6ca https://www.nowcoder.com/discuss/396603397997162496 https://www.cnblogs.com/vipsoft/p/17859847.html https://rivers.chaitin.cn/blog/cq940510lnechd242kvg https://zhuanlan.zhihu.com/p/407710777 https://www.yisu.com/zixun/729033.html https://blog.csdn.net/Arvin627/article/details/147621176 https://www.invicti.com/web-vulnerability-scanner/vulnerabilities/spring-boot-misconfiguration-spring-boot-actuator-shutdown-endpoint-is-web-exposed https://www.herodevs.com/blog-posts/cve-2026-40976-spring-boot-4-0-actuator-authorization-bypass https://www.acunetix.com/vulnerabilities/web/spring-boot-misconfiguration-spring-boot-actuator-shutdown-endpoint-is-web-exposed/ https://r0yanx.com/2020/06/05/Spring-Boot-Actuators%E6%9C%AA%E6%8E%88%E6%9D%83GetShell/
Related VulnerabilitiesNacos /nacos/actuator 未授权访问漏洞Spring Actuator 未授权访问漏洞PoCspringboot-sbom: Spring Boot Actuator SBOM - ExposurePoCspringboot-httpexchanges: Detects Springboot HTTP Exchanges ActuatorPoCspringboot-x-application-context: Spring Boot `X-Application-Context` Header Exposurespringboot-actuator-unauth: Springboot Actuator UnauthPoCCVE-2021-21234: Spring Boot Actuator Logview Directory TraversalPoCCVE-2025-34026: Versa Concerto Actuator Endpoint - Authentication BypassPoCCVE-2025-46822: Java-springboot-codebase 1.1 - Arbitrary File ReadPoCgcloud-vertexai-idle-shutdown: Idle Shutdown Not Enabled for Vertex AI NotebooksPoCcrash-on-audit-fail: Shutdown on Audit Failure CheckPoCremote-system-shutdown: Remote System Forced Shutdown Privilege Check