SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-47850

MEDIUM · CVSS 4.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Spring Data REST is vulnerable due to its failure to preserve the persisted version property of an aggregate root when processing HTTP PUT requests for immutable target types. This can lead to inconsistencies in data versioning, potentially affecting application integrity and reliability. Organizations using affected versions of Spring Data REST should prioritize remediation to mitigate risks associated with data integrity and application behavior.

CVE
CVE-2026-47850
Severity
MEDIUM
CVSS
4.3
EPSS
0.18%

Original NVD Description

Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root when handling an HTTP PUT against an immutable target type. Spring Data REST 5.1.0 Spring Data REST 5.0.0 - 5.0.6 Spring Data REST 4.5.0 - 4.5.12 Spring Data REST 4.0.0 - 4.4.15 Spring Data REST 3.7.20 and earlier

Related CVEs

Other vulnerabilities affecting the same vendor(s)