Arbitrary Code Execution Vulnerability in Spring Security Framework by Pivotal Software
CVE-2026-41003
7.6HIGH
What is CVE-2026-41003?
A vulnerability exists in the Spring Security framework that allows an attacker with the ability to manipulate values in RelyingPartyRegistration to potentially execute arbitrary code on HTML forms that are produced by Spring Security filters. This could lead to unauthorized access and manipulation if exploited.
Affected Version(s)
Spring Security 5.7.0 < 5.7.24
Spring Security 5.8.0 < 5.8.26
Spring Security 6.3.0 < 6.3.17
