Improper access control in Spring AI - CVE-2026-59318
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to invoke a tool that was not made available to the current request, potentially leading to privilege escalation.
The vulnerability exists due to improper access control in DefaultToolCallingManager tool calling support when dispatching tool calls after processing prompt-injected input. A remote user can cause dispatch of an unadvertised tool to invoke a tool that was not made available to the current request, potentially leading to privilege escalation.
User interaction is required.
Affected software
Library Support for Spring
How to mitigate CVE-2026-59318
Library Support for Spring - update to 3.5.19