SMB Protocol Vulnerability in Spring Integration by VMware
CVE-2026-59293
6.6MEDIUM
What is CVE-2026-59293?
The vulnerability in Spring Integration occurs when the application does not explicitly set smbMinVersion, leading the jCIFS client to potentially negotiate the use of SMB1/CIFS. This version lacks essential security features like mandatory signing and encryption, making it susceptible to NTLM relay attacks and man-in-the-middle content tampering. Users are strongly advised to update to the latest version of Spring Integration to mitigate this security risk.
Affected Version(s)
Spring Integration 7.1.0
Spring Integration 7.0.0 <= 7.0.5
Spring Integration 6.5.0 <= 6.5.10
