Database Manipulation Vulnerability in Spring Security by Pivotal Software
CVE-2026-40993
7.3HIGH
What is CVE-2026-40993?
A vulnerability exists in Spring Security that allows an attacker with write permissions to the database managed by JdbcAssertingPartyMetadataRepository to store malicious serialized payloads in critical credential columns. This can lead to potential exploitation where attackers manipulate verification and encryption credentials, risking the integrity of sensitive data. The affected versions range from Spring Security 7.0.0 to 7.0.5, making it essential for users to update to secure their systems.
Affected Version(s)
Spring Security 7.0.0 < 7.0.5.1
