CVE-2026-41696
Estado: AnalizadaMedia (5.9)—
Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient validation of the bound parameter. An attacker can supply a crafted string to break out of the intended regular expression quoting.
Affected versions: Spring Data MongoDB 5.0.0 through 5.0.5; 4.5.0 through 4.5.11; 4.4.0 through 4.4.14; 4.3.0 through 4.3.16; 4.2.0 through 4.2.15; 4.1.0 through 4.1.14; 4.0.0 through 4.0.15; 3.4.0 through 3.4.19.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 5.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.33%
- Percentil entre todas las CVEs puntuadas: 24
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-943
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-41696",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-41696",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-06-10T17:52:05.245642Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@vmware.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.9,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "security@vmware.com",
"affectedData": [
{
"vendor": "Spring",
"product": "Spring Data MongoDB",
"versions": [
{
"status": "affected",
"version": "5.0.0",
"lessThan": "5.0.6",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.5.0",
"lessThan": "4.5.12",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.4.0",
"lessThan": "4.4.15",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.3.0",
"lessThan": "4.3.17",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.2.0",
"lessThan": "4.2.16",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.1.0",
"lessThan": "4.1.15",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.0.0",
"lessThan": "4.0.16",
"versionType": "custom"
},
{
"status": "affected",
"version": "3.4.0",
"lessThan": "3.4.20",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-06-10T00:16:50.800",
"references": [
{
"url": "https://spring.io/security/cve-2026-41696",
"tags": [
"Vendor Advisory"
],
"source": "security@vmware.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security@vmware.com",
"description": [
{
"lang": "en",
"value": "CWE-943"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient validation of the bound parameter. An attacker can supply a crafted string to break out of the intended regular expression quoting.\n\nAffected versions:\nSpring Data MongoDB 5.0.0 through 5.0.5; 4.5.0 through 4.5.11; 4.4.0 through 4.4.14; 4.3.0 through 4.3.16; 4.2.0 through 4.2.15; 4.1.0 through 4.1.14; 4.0.0 through 4.0.15; 3.4.0 through 3.4.19."
},
{
"lang": "es",
"value": "Los métodos de consulta de repositorio de Spring Data MongoDB anotados con @Query que utilizan el enlace de parámetros regex realizan una validación insuficiente del parámetro enlazado. Un atacante puede proporcionar una cadena manipulada para escapar de la comilla de expresión regular prevista.\n\nVersiones afectadas:\nSpring Data MongoDB 5.0.0 hasta 5.0.5; 4.5.0 hasta 4.5.11; 4.4.0 hasta 4.4.14; 4.3.0 hasta 4.3.16; 4.2.0 hasta 4.2.15; 4.1.0 hasta 4.1.14; 4.0.0 hasta 4.0.15; 3.4.0 hasta 3.4.19."
}
],
"lastModified": "2026-07-23T09:10:00.113",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:vmware:spring_data_mongodb:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7E55F58B-81A9-4912-9573-5B452BC55E51",
"versionEndExcluding": "3.4.20",
"versionStartIncluding": "3.4.0"
},
{
"criteria": "cpe:2.3:a:vmware:spring_data_mongodb:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1BEBCD2A-409F-4DEF-AF40-9EEC62A099C2",
"versionEndIncluding": "4.0.15",
"versionStartIncluding": "4.0.0"
},
{
"criteria": "cpe:2.3:a:vmware:spring_data_mongodb:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A5820FCC-F941-4399-B2B9-EDC5EE3F6953",
"versionEndIncluding": "4.1.14",
"versionStartIncluding": "4.1.0"
},
{
"criteria": "cpe:2.3:a:vmware:spring_data_mongodb:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "67E36C20-FF20-4F82-B161-74E3838D67FD",
"versionEndIncluding": "4.2.15",
"versionStartIncluding": "4.2.0"
},
{
"criteria": "cpe:2.3:a:vmware:spring_data_mongodb:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A5BFEA5F-410F-441E-9DC9-34C03B566E50",
"versionEndExcluding": "4.3.17",
"versionStartIncluding": "4.3.0"
},
{
"criteria": "cpe:2.3:a:vmware:spring_data_mongodb:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F0BD2306-031F-4D72-BC3E-19ACB886E73D",
"versionEndExcluding": "4.4.15",
"versionStartIncluding": "4.4.0"
},
{
"criteria": "cpe:2.3:a:vmware:spring_data_mongodb:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D21BA806-10F0-4DA5-9DB6-A669FA01E1CE",
"versionEndExcluding": "4.5.11.1",
"versionStartIncluding": "4.5.0"
},
{
"criteria": "cpe:2.3:a:vmware:spring_data_mongodb:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5F530EDE-94AE-42FA-A6FE-458CAC0B7EF3",
"versionEndExcluding": "5.0.5.1",
"versionStartIncluding": "5.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@vmware.com"
}