Protection mechanism failure in Spring Framework - CVE-2026-41852
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote attacker to invoke unintended application logic.
The vulnerability exists due to improper restriction of operations within the Spring Expression Language evaluation logic in SpEL expression evaluation when evaluating untrusted or user-controlled expressions. A remote attacker can supply a crafted expression to invoke unintended application logic.
Arbitrary zero-argument method invocation is possible even within restricted or read-only contexts.