CVE-2026-41003

Updated on 09 Jun 2026

Severity

7.6 High severity

Details

CVSS score
7.6
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N

Overview

About vulnerability

An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generated by Spring Security filters.

Details

Affected product:
Apache CXF , Apache Log4j , Spring , grails-core
Affected packages:
Spring Integration @ 5.5.19 (+2934 more)

Fixes