SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-59307

HIGH · CVSS 8 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability affects Spring Integration versions 6.4.0 through 7.1.0, where improper handling of deserialization in JdbcMessageStore can lead to unauthorized access or manipulation of data. Operators using the addAllowedPatterns(...) method to restrict deserialization are left unprotected when the store is managed by Spring, potentially allowing attackers to exploit this weakness. Organizations utilizing affected Spring Integration versions should prioritize patching to mitigate the risk of data breaches and unauthorized actions.

CVE
CVE-2026-59307
Severity
HIGH
CVSS
8
EPSS
0.35%

Original NVD Description

An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deserialization receives no protection at all when the store is a Spring-managed bean. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12

Related CVEs

Other vulnerabilities affecting the same vendor(s)