HIGH
Unfiltered Java Native Deserialization of SAML 2.0 Asserting Party Credentials BLOB Database Entry
Published Jun 9, 2026
7.3
HIGHCVSS 3.1
EPSS 0.30%
Description
An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_asserting_party_metadata) may be able to store malicious serialized payloads in the columns containing the collection of verification or encryption credentials (verification_credentials and encryption_credentials, respectively).
Affected versions: Spring Security 7.0.0 through 7.0.5.
Affected products
-
- Version 7.0.0StatusaffectedConstraints<7.0.5.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Spring | Spring Security | unaffected |
|
- ≥ 7.0.0 · < 7.0.5.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35886 Advisory
- https://github.com/advisories/GHSA-2q7c-5gjm-7q23 Advisory
- https://github.com/spring-projects/spring-security/releases/tag/7.0.6
- https://nvd.nist.gov/vuln/detail/CVE-2026-40993
- https://spring.io/security/cve-2026-40993 Vendor Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner vmware
Published Jun 9, 2026
Updated Jun 27, 2026
Reserved Apr 16, 2026
Link CVE-2026-40993
CISA Vulnrichment
Updated Jun 10, 2026
ENISA EUVD
EUVD-2026-35886 GHSA-2Q7C-5GJM-7Q23 Assigner vmware
Published Jun 9, 2026
Updated Jun 27, 2026
Exploited since n/a
Link EUVD-2026-35886