Database Manipulation Vulnerability in Spring Security by Pivotal Software
CVE-2026-40993

7.3HIGH

Key Information:

Vendor

Spring

Vendor
CVE Published:
9 June 2026

What is CVE-2026-40993?

A vulnerability exists in Spring Security that allows an attacker with write permissions to the database managed by JdbcAssertingPartyMetadataRepository to store malicious serialized payloads in critical credential columns. This can lead to potential exploitation where attackers manipulate verification and encryption credentials, risking the integrity of sensitive data. The affected versions range from Spring Security 7.0.0 to 7.0.5, making it essential for users to update to secure their systems.

Affected Version(s)

Spring Security 7.0.0 < 7.0.5.1

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.