SMB Protocol Vulnerability in Spring Integration by VMware
CVE-2026-59293

6.6MEDIUM

Key Information:

Vendor

Spring

Vendor
CVE Published:
27 August 2026

What is CVE-2026-59293?

The vulnerability in Spring Integration occurs when the application does not explicitly set smbMinVersion, leading the jCIFS client to potentially negotiate the use of SMB1/CIFS. This version lacks essential security features like mandatory signing and encryption, making it susceptible to NTLM relay attacks and man-in-the-middle content tampering. Users are strongly advised to update to the latest version of Spring Integration to mitigate this security risk.

Affected Version(s)

Spring Integration 7.1.0

Spring Integration 7.0.0 <= 7.0.5

Spring Integration 6.5.0 <= 6.5.10

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.