Authorization Flaw in Spring GraphQL by Spring Framework
CVE-2026-41856

7.5HIGH

Key Information:

Vendor

Spring

Vendor
CVE Published:
11 June 2026

What is CVE-2026-41856?

The Spring GraphQL framework has a vulnerability in its annotation detection mechanism that may fail to properly resolve annotations on methods in type hierarchies. This oversight could lead to security annotations being bypassed at runtime, particularly impacting authorization decisions when those annotations are crucial for securing sensitive operations.

Affected Version(s)

Spring for GraphQL 2.0.0 < 2.0.3.1

Spring for GraphQL 1.4.0 < 1.4.5.1

Spring for GraphQL 1.3.0 < 1.3.9

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.