Protection mechanism failure in Spring Framework - CVE-2026-41852

 

Protection mechanism failure in Spring Framework - CVE-2026-41852

Published: August 31, 2026


Vulnerability identifier: #VU146412
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-41852
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to invoke unintended application logic.

The vulnerability exists due to improper restriction of operations within the Spring Expression Language evaluation logic in SpEL expression evaluation when evaluating untrusted or user-controlled expressions. A remote attacker can supply a crafted expression to invoke unintended application logic.

Arbitrary zero-argument method invocation is possible even within restricted or read-only contexts.


Affected software

Spring Framework

How to mitigate CVE-2026-41852

Install security update from vendor's website.

Spring Framework - addressed in versions 5.3.49, 6.1.28, 6.2.18.1, 6.2.19, 7.0.7.1, 7.0.8

External References

Related Security Bulletins