Session ID Escalation Vulnerability in Spring Framework by VMware
CVE-2026-41839

4.2MEDIUM

Key Information:

Vendor

Spring

Vendor
CVE Published:
9 June 2026

What is CVE-2026-41839?

A vulnerability exists within VMware's Spring Framework that allows an attacker to escalate their access by substituting a known session ID with that of an authenticated user. This type of attack can occur if a WebFlux application is compromised through methods such as cross-site scripting (XSS), enabling unauthorized access to user sessions. It is critical for organizations utilizing the affected versions to apply security updates promptly and implement robust security measures to safeguard against this exploitation.

Affected Version(s)

Spring Framework 7.0.0 < 7.0.7.1

Spring Framework 6.2.0 < 6.2.18.1

Spring Framework 6.1.0 < 6.1.28

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.