CVE-2026-41856
The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue if such annotations are used for authorization decisions. When all conditions are met, security annotations can be ignored at runtime.
Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8; 1.0.0 through 1.0.6.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.39%
- Percentil entre todas las CVEs puntuadas: 31
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access60 %
Inferido por reglas deterministas a partir del vector CVSS y la CWE. Solo orientativo.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-284
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-41856",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-41856",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-06-11T15:16:49.624069Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@vmware.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@vmware.com",
"affectedData": [
{
"vendor": "Spring",
"product": "Spring for GraphQL",
"versions": [
{
"status": "affected",
"version": "2.0.0",
"lessThan": "2.0.3.1",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.4.0",
"lessThan": "1.4.5.1",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.3.0",
"lessThan": "1.3.9",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.0.0",
"lessThan": "1.0.7",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-06-11T07:16:28.513",
"references": [
{
"url": "https://spring.io/security/cve-2026-41856",
"tags": [
"Vendor Advisory"
],
"source": "security@vmware.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security@vmware.com",
"description": [
{
"lang": "en",
"value": "CWE-284"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue if such annotations are used for authorization decisions. When all conditions are met, security annotations can be ignored at runtime.\n\nAffected versions:\nSpring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8; 1.0.0 through 1.0.6."
},
{
"lang": "es",
"value": "El mecanismo de detección de anotaciones de Spring GraphQL para capturadores de datos @Controller podría no resolver correctamente las anotaciones en métodos dentro de jerarquías de tipos. Esto puede ser un problema si dichas anotaciones se utilizan para decisiones de autorización. Cuando se cumplen todas las condiciones, las anotaciones de seguridad pueden ser ignoradas en tiempo de ejecución.\n\nVersiones afectadas:\nSpring for GraphQL 2.0.0 hasta 2.0.3; 1.4.0 hasta 1.4.5; 1.3.0 hasta 1.3.8; 1.0.0 hasta 1.0.6."
}
],
"lastModified": "2026-07-23T09:10:00.113",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:vmware:spring_for_graphql:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8081FE74-21D1-4A99-BD7D-EC79761CC5FE",
"versionEndExcluding": "1.0.7",
"versionStartIncluding": "1.0.0"
},
{
"criteria": "cpe:2.3:a:vmware:spring_for_graphql:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7F58A3E0-F0B6-41B9-9257-D20CF2396F2B",
"versionEndExcluding": "1.3.9",
"versionStartIncluding": "1.3.0"
},
{
"criteria": "cpe:2.3:a:vmware:spring_for_graphql:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "35C81108-F60D-4E58-9ADA-900321B3BEEC",
"versionEndExcluding": "1.4.5.1",
"versionStartIncluding": "1.4.0"
},
{
"criteria": "cpe:2.3:a:vmware:spring_for_graphql:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "061D9CA8-C971-42ED-8032-B2E2A2C6B864",
"versionEndExcluding": "2.0.3.1",
"versionStartIncluding": "2.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@vmware.com"
}