SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-47849

HIGH · CVSS 7.1 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Spring Data REST is vulnerable to unauthorized modification of identifier and version properties through JSON Patch requests, which could lead to data integrity issues and unauthorized access. This vulnerability affects multiple versions of Spring Data REST, including 5.1.0 and earlier, making it critical for developers and organizations using these versions to prioritize patching to mitigate potential exploitation. Immediate action is recommended for those managing applications that rely on Spring Data REST to ensure data security and compliance.

CVE
CVE-2026-47849
Severity
HIGH
CVSS
7.1
EPSS
0.27%

Original NVD Description

Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Patch (application/json-patch+json) requests. Spring Data REST 5.1.0 Spring Data REST 5.0.0 - 5.0.6 Spring Data REST 4.5.0 - 4.5.12 Spring Data REST 4.0.0 - 4.4.15 Spring Data REST 3.7.20 and earlier

Related CVEs

Other vulnerabilities affecting the same vendor(s)