Improper access control in Spring Cloud Function - CVE-2026-59299
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information and modify data.
The vulnerability exists due to improper access control in composition lookup in Spring Cloud Function when resolving composed functions. A remote privileged user can poison the base function lookup to disclose sensitive information and modify data.
User interaction is required.