SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-47880

MEDIUM · CVSS 5.4 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Spring Integration versions 5.5.21 and earlier, as well as 6.4.0 to 7.1.0, are vulnerable to manipulation of JMS properties by any producer publishing to a JMS destination. This allows attackers to inject arbitrary values into the Spring Integration MessageHeaders, potentially leading to unauthorized access or message processing issues. Organizations using these versions should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-47880
Severity
MEDIUM
CVSS
5.4
EPSS
0.19%

Original NVD Description

A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component can set String JMS properties named replyChannel, errorChannel, or json__TypeId__ which are copied verbatim into the Spring Integration MessageHeaders. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier

Related CVEs

Other vulnerabilities affecting the same vendor(s)