Incorrect authorization in Spring Framework - CVE-2026-47892
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass header-based access restrictions.
The vulnerability exists due to improper access control in WebFlux functional endpoints when processing pre-flight requests with DispatcherServlet. A remote attacker can send a specially crafted pre-flight request to bypass header-based access restrictions.
Only WebFlux applications using functional endpoints and deployed with DispatcherServlet are affected.
Affected software
Library Support for Spring
How to mitigate CVE-2026-47892
Library Support for Spring - update to 3.5.19