Insecure Default Initialization of Resource in Spring Integration - CVE-2026-59293
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote user to intercept or alter transferred files and capture NTLM credentials.
The vulnerability exists due to insecure default configuration in the SMB adapter jCIFS client configuration when negotiating the SMB protocol dialect. A remote privileged user can downgrade the connection to smb1/cifs in a machine-in-the-middle position to intercept or alter transferred files and capture NTLM credentials.
The issue occurs unless the application explicitly raises smbMinVersion.
Affected software
Library Support for Spring
How to mitigate CVE-2026-59293
Library Support for Spring - update to 3.5.19