SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-59283

CRITICAL · CVSS 9.1 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Applications utilizing Spring Framework versions 5.2.25.RELEASE through 7.0.8 that evaluate Spring Expression Language (SpEL) expressions with an active SimpleEvaluationContext may be susceptible to a safety guard bypass vulnerability. This flaw could allow attackers to execute arbitrary expressions, potentially leading to unauthorized access or manipulation of application data. Organizations using affected Spring Framework versions should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-59283
Severity
CRITICAL
CVSS
9.1
EPSS
0.37%

Original NVD Description

Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable to a safety guard bypass when the SpEL expression compiler is active. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier

Related CVEs

Other vulnerabilities affecting the same vendor(s)