PT-2026-49305 · Vmware+2 · Gemfire+3

·

CVE-2026-47835

·

Published

2026-06-15

·

Updated

2026-06-17

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Spring AI versions prior to 1.0.9 Spring AI versions prior to 1.1.8
Description Special characters can be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire VectorDB. This issue affects the spring-ai-elasticsearch-store, spring-ai-opensearch-store, and spring-ai-gemfire-store components.
Recommendations Update to version 1.0.9 for versions in the 1.0.x branch. Update to version 1.1.8 for versions in the 1.1.x branch.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47835
GHSA-CMWH-W62W-R2MF

Affected Products

Elasticsearch
Gemfire
Opensearch
Spring Ai