AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-23258

MEDIUM · CVSS 4.2 EPSS 0.70%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-12-02 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2021-23258
Severity
MEDIUM
CVSS
4.2
EPSS
0.70%

Original NVD Description

Authenticated users with Administrator or Developer roles may execute OS commands by SPEL Expression in Spring beans. SPEL Expression does not have security restrictions, which will cause attackers to execute arbitrary commands remotely (RCE).