SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-47834

MEDIUM · CVSS 4.8 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Spring Data JPA versions 3.0.0 to 4.1.0 are vulnerable to a bypass in Sort validation, allowing attackers to submit crafted payloads from untrusted sources. This could lead to unauthorized data access or manipulation, impacting the integrity of applications relying on these versions. Organizations using affected Spring Data JPA versions should prioritize remediation to mitigate potential exploitation risks.

CVE
CVE-2026-47834
Severity
MEDIUM
CVSS
4.8
EPSS
0.21%

Original NVD Description

Spring Data JPA's Sort validation can be bypassed when parameters containing crafted payload are accepted from untrusted sources. Spring Data JPA 4.1.0 Spring Data JPA 4.0.0 - 4.0.6 Spring Data JPA 3.5.0 - 3.5.13 Spring Data JPA 3.0.0 - 3.4.15

Related CVEs

Other vulnerabilities affecting the same vendor(s)