AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2018-1258

HIGH · CVSS 8.8 EPSS 2.40%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-05-11 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2018-1258
Severity
HIGH
CVSS
8.8
EPSS
2.40%

Original Filing — NVD Description

Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.