CVE-2026-41852: Spring Framework Arbitrary Method Invocation in SpEL Expressions
A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker to invoke unintended application logic. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41852?
CVE-2026-41852 has a severity rating of low, with a score of 3.7.
How do I fix CVE-2026-41852?
To fix CVE-2026-41852, upgrade to versions of Spring Framework later than 7.0.7 or 6.2.0.
What components are affected by CVE-2026-41852?
CVE-2026-41852 affects the Spring Framework, particularly versions 7.0.0 through 7.0.7 and 6.2.0.
What types of attacks does CVE-2026-41852 allow?
CVE-2026-41852 could allow for arbitrary zero-argument method invocation, potentially leading to unintended application logic execution.
Is user interaction required for exploiting CVE-2026-41852?
No, exploiting CVE-2026-41852 does not require user interaction, as it is classified with UI:N.