PT-2026-48324 · Vmware · Spring Data Rest

CVE-2026-41728

·

Published

2026-06-09

·

Updated

2026-09-01

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Spring Data REST versions 3.7.0 through 3.7.19 Spring Data REST versions 4.3.0 through 4.3.16 Spring Data REST versions 4.4.0 through 4.4.14 Spring Data REST versions 4.5.0 through 4.5.11 Spring Data REST versions 5.0.0 through 5.0.5
Description The JSON Patch (application/json-patch+json) implementation fails to apply the write-access filter to intermediate path segments when resolving a multi-segment JSON Pointer. This allows unauthorized write access through a JSON Patch bypass.
Recommendations Update Spring Data REST versions 3.7.0 through 3.7.19 to a fixed version. Update Spring Data REST versions 4.3.0 through 4.3.16 to a fixed version. Update Spring Data REST versions 4.4.0 through 4.4.14 to a fixed version. Update Spring Data REST versions 4.5.0 through 4.5.11 to a fixed version. Update Spring Data REST versions 5.0.0 through 5.0.5 to a fixed version.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41728
GHSA-CV39-X4C6-HHP2

Affected Products

Spring Data Rest