Arbitrary Method Invocation Vulnerability in Spring Framework by VMware
CVE-2026-41852
3.7LOW
What is CVE-2026-41852?
A flaw in the Spring Expression Language (SpEL) evaluation logic enables arbitrary zero-argument method invocation. This vulnerability can be exploited, allowing attackers to trigger unintended application behaviors even in restricted contexts. The affected versions of the Spring Framework pose a significant risk, allowing unauthorized access to application logic that is otherwise guarded.
Affected Version(s)
Spring Framework 7.0.0 < 7.0.7.1
Spring Framework 6.2.0 < 6.2.18.1
Spring Framework 6.1.0 < 6.1.28
