« Back to list

CVE-2026-59288

Status: ModifiedHigh (7.4)—

The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. An attacker can share a malicious URL so that the victim's browser might leak confidential information to the attacker's website. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.1.0 - 1.3.9 Spring for GraphQL 1.0.0 - 1.0.7

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

🎯 ATT&CK techniques

How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.

XSS en GraphiQL con UI:R (interacción requerida para hacer clic en URL maliciosa). Víctima filtra datos confidenciales al sitio atacante (lectura de información local).

Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.

🛡️ ATT&CK mitigations that cover these techniques

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2026-59288",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-59288",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-09-01T15:35:54.539496Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.4,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "Spring",
          "product": "Spring for GraphQL",
          "versions": [
            {
              "status": "affected",
              "version": "2.0.0",
              "versionType": "custom",
              "lessThanOrEqual": "2.0.4"
            },
            {
              "status": "affected",
              "version": "1.4.0",
              "versionType": "custom",
              "lessThanOrEqual": "1.4.6"
            },
            {
              "status": "affected",
              "version": "1.1.0",
              "versionType": "custom",
              "lessThanOrEqual": "1.3.9"
            },
            {
              "status": "affected",
              "version": "1.0.0",
              "versionType": "custom",
              "lessThanOrEqual": "1.0.7"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-08-27T20:17:55.013",
  "references": [
    {
      "url": "https://spring.io/security/cve-2026-59288",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@vmware.com"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. An attacker can share a malicious URL so that the victim's browser might leak confidential information to the attacker's website.\nSpring for GraphQL 2.0.0 - 2.0.4\nSpring for GraphQL 1.4.0 - 1.4.6\nSpring for GraphQL 1.1.0 - 1.3.9\nSpring for GraphQL 1.0.0 - 1.0.7"
    }
  ],
  "lastModified": "2026-09-01T16:17:06.887",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:spring_for_graphql:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "82E7D069-022A-4C69-889B-05B229EB70D1",
              "versionEndExcluding": "1.0.8",
              "versionStartIncluding": "1.0.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_for_graphql:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "452FAD3A-5BB4-4A2E-85E8-53C626FF3FB8",
              "versionEndExcluding": "1.3.10",
              "versionStartIncluding": "1.1.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_for_graphql:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F222EDF3-FE28-4B32-B21A-43F8333A0519",
              "versionEndExcluding": "1.4.7",
              "versionStartIncluding": "1.4.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_for_graphql:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E387E391-B5B2-48DD-A76E-EC051BBF0703",
              "versionEndExcluding": "2.0.4.1",
              "versionStartIncluding": "2.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@vmware.com"
}