Arbitrary Code Execution Vulnerability in Spring Security Framework by Pivotal Software
CVE-2026-41003

7.6HIGH

Key Information:

Vendor

Spring

Vendor
CVE Published:
9 June 2026

What is CVE-2026-41003?

A vulnerability exists in the Spring Security framework that allows an attacker with the ability to manipulate values in RelyingPartyRegistration to potentially execute arbitrary code on HTML forms that are produced by Spring Security filters. This could lead to unauthorized access and manipulation if exploited.

Affected Version(s)

Spring Security 5.7.0 < 5.7.24

Spring Security 5.8.0 < 5.8.26

Spring Security 6.3.0 < 6.3.17

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.