Data Integrity Vulnerability in Spring Data REST by Pivotal
CVE-2026-47849

7.1HIGH

Key Information:

Vendor

Spring

Vendor
CVE Published:
27 August 2026

What is CVE-2026-47849?

A vulnerability exists in Spring Data REST that allows attackers to manipulate identifier (@Id) and version (@Version) properties through RFC 6902 JSON Patch (application/json-patch+json) requests. This weakness enables unauthorized alteration of critical data elements, potentially leading to data integrity issues across applications utilizing these versions of Spring Data REST.

Affected Version(s)

Spring Data REST 5.1.0

Spring Data REST 5.0.0 <= 5.0.6

Spring Data REST 4.5.0 <= 4.5.12

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.