CVE-2026-59293

Updated on 27 Aug 2026

Severity

4.0 Medium severity

Details

CVSS score
4.0
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Overview

About vulnerability

Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate down to SMB1/CIFS, which lacks mandatory signing/encryption and is vulnerable to NTLM relay and content-tampering MITM. An on-path attacker can downgrade the dialect, intercept or alter files moved by the SMB adapters, or capture NTLM credentials.

Details

Affected product:
Spring
Affected packages:
Spring Integration @ 6.4.10 (+570 more)