3.7
/ 10
LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Description
A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker to invoke unintended application logic.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Basic Information
ID
CVE-2026-41852
Source
vmware
Published
Jun 9, 2026 at 03:51
Affected Product
Vendor
Spring
Product
Spring Framework
Version
7.0.0
Affected Versions
Spring Spring Framework 7.0.0
Spring Spring Framework 6.2.0
Spring Spring Framework 6.1.0
Spring Spring Framework 5.3.0
Spring Spring Framework 6.2.0
Spring Spring Framework 6.1.0
Spring Spring Framework 5.3.0