SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-47842

MEDIUM · CVSS 6.5 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Applications utilizing AesBytesEncryptor with a two-argument constructor or a null IV generator in CBC mode are vulnerable to encryption weaknesses due to the use of a null (all-zero) initialization vector. This flaw can lead to predictable ciphertext, potentially allowing attackers to decrypt sensitive data or perform other cryptographic attacks. Organizations using affected versions of Spring Security should prioritize remediation to safeguard their data integrity and confidentiality.

CVE
CVE-2026-47842
Severity
MEDIUM
CVSS
6.5
EPSS
0.10%

Original NVD Description

Applications using AesBytesEncryptor with the two-argument constructor or when passing a null IV generator and CBC as the encryption mode encrypt data with AES/CBC using a null (all-zero) initialization vector. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18 Spring Security 5.8.0 - 5.8.27 Spring Security 5.7.0 - 5.7.25

Related CVEs

Other vulnerabilities affecting the same vendor(s)