CVE-2026-40993

HIGH

Unfiltered Java Native Deserialization of SAML 2.0 Asserting Party Credentials BLOB Database Entry

Title source: cna
STIX 2.1

Description

An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_asserting_party_metadata) may be able to store malicious serialized payloads in the columns containing the collection of verification or encryption credentials (verification_credentials and encryption_credentials, respectively). Affected versions: Spring Security 7.0.0 through 7.0.5.

References (1)

Core 1

Scores

CVSS v3 7.3
EPSS 0.0009
EPSS Percentile 0.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-502
Status published
Products (1)
Spring/Spring Security 7.0.0 - 7.0.6
Published Jun 10, 2026
Tracked Since Jun 10, 2026