SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-47887

MEDIUM · CVSS 6.1 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Spring MVC applications utilizing UrlFileNameViewController without a configured prefix are susceptible to open redirect vulnerabilities, allowing attackers to manipulate URLs and potentially redirect users to malicious sites. This issue affects multiple versions of the Spring Framework, specifically from 5.2.25.RELEASE up to 7.0.8. Organizations using these versions should prioritize remediation to mitigate the risk of phishing attacks and unauthorized access.

CVE
CVE-2026-47887
Severity
MEDIUM
CVSS
6.1
EPSS
0.17%

Original NVD Description

A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier

Related CVEs

Other vulnerabilities affecting the same vendor(s)