PT-2026-48324 · Vmware · Spring Data Rest
CVE-2026-41728
·
Published
2026-06-09
·
Updated
2026-09-01
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Spring Data REST versions 3.7.0 through 3.7.19
Spring Data REST versions 4.3.0 through 4.3.16
Spring Data REST versions 4.4.0 through 4.4.14
Spring Data REST versions 4.5.0 through 4.5.11
Spring Data REST versions 5.0.0 through 5.0.5
Description
The JSON Patch (application/json-patch+json) implementation fails to apply the write-access filter to intermediate path segments when resolving a multi-segment JSON Pointer. This allows unauthorized write access through a JSON Patch bypass.
Recommendations
Update Spring Data REST versions 3.7.0 through 3.7.19 to a fixed version.
Update Spring Data REST versions 4.3.0 through 4.3.16 to a fixed version.
Update Spring Data REST versions 4.4.0 through 4.4.14 to a fixed version.
Update Spring Data REST versions 4.5.0 through 4.5.11 to a fixed version.
Update Spring Data REST versions 5.0.0 through 5.0.5 to a fixed version.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spring Data Rest