Improper access control in Spring AI - CVE-2026-59318

 

Improper access control in Spring AI - CVE-2026-59318

Published: August 31, 2026


Vulnerability identifier: #VU146399
CSH Severity: Low
CVSS v4: 5.8 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-59318
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to invoke a tool that was not made available to the current request, potentially leading to privilege escalation.

The vulnerability exists due to improper access control in DefaultToolCallingManager tool calling support when dispatching tool calls after processing prompt-injected input. A remote user can cause dispatch of an unadvertised tool to invoke a tool that was not made available to the current request, potentially leading to privilege escalation.

User interaction is required.


Affected software

Spring AI
Library Support for Spring

How to mitigate CVE-2026-59318

Install security update from vendor's website.

Spring AI - addressed in versions 1.0.10, 1.1.9, 2.0.0.1, 2.0.1
Library Support for Spring - update to 3.5.19

External References

Related Security Bulletins