« Volver al listado

CVE-2026-41856

Estado: AnalizadaAlta (7.5)—

The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue if such annotations are used for authorization decisions. When all conditions are met, security annotations can be ignored at runtime.

Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8; 1.0.0 through 1.0.6.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Inferido por reglas deterministas a partir del vector CVSS y la CWE. Solo orientativo.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-41856",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-41856",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-11T15:16:49.624069Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@vmware.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "Spring",
          "product": "Spring for GraphQL",
          "versions": [
            {
              "status": "affected",
              "version": "2.0.0",
              "lessThan": "2.0.3.1",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "1.4.0",
              "lessThan": "1.4.5.1",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "1.3.0",
              "lessThan": "1.3.9",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "1.0.0",
              "lessThan": "1.0.7",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-06-11T07:16:28.513",
  "references": [
    {
      "url": "https://spring.io/security/cve-2026-41856",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@vmware.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@vmware.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue if such annotations are used for authorization decisions. When all conditions are met, security annotations can be ignored at runtime.\n\nAffected versions:\nSpring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8; 1.0.0 through 1.0.6."
    },
    {
      "lang": "es",
      "value": "El mecanismo de detección de anotaciones de Spring GraphQL para capturadores de datos @Controller podría no resolver correctamente las anotaciones en métodos dentro de jerarquías de tipos. Esto puede ser un problema si dichas anotaciones se utilizan para decisiones de autorización. Cuando se cumplen todas las condiciones, las anotaciones de seguridad pueden ser ignoradas en tiempo de ejecución.\n\nVersiones afectadas:\nSpring for GraphQL 2.0.0 hasta 2.0.3; 1.4.0 hasta 1.4.5; 1.3.0 hasta 1.3.8; 1.0.0 hasta 1.0.6."
    }
  ],
  "lastModified": "2026-07-23T09:10:00.113",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:spring_for_graphql:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8081FE74-21D1-4A99-BD7D-EC79761CC5FE",
              "versionEndExcluding": "1.0.7",
              "versionStartIncluding": "1.0.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_for_graphql:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7F58A3E0-F0B6-41B9-9257-D20CF2396F2B",
              "versionEndExcluding": "1.3.9",
              "versionStartIncluding": "1.3.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_for_graphql:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "35C81108-F60D-4E58-9ADA-900321B3BEEC",
              "versionEndExcluding": "1.4.5.1",
              "versionStartIncluding": "1.4.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_for_graphql:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "061D9CA8-C971-42ED-8032-B2E2A2C6B864",
              "versionEndExcluding": "2.0.3.1",
              "versionStartIncluding": "2.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@vmware.com"
}