Privilege Escalation Vulnerability in Spring AI Tool Calling Support
CVE-2026-59318

6.5MEDIUM

Key Information:

Vendor

Spring

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-59318?

A vulnerability exists in Spring AI's tool calling support mechanism, where the per-request tool list is poorly enforced. This allows for conditions under which tools not explicitly available to the current request can be invoked, posing a risk of privilege escalation that could enable unauthorized access to sensitive functionalities or data.

Affected Version(s)

Spring AI 2.0.0

Spring AI 1.1.0 <= 1.1.8

Spring AI 1.0.0 <= 1.0.9

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.