SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-47892

CRITICAL · CVSS 9.8 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

WebFlux applications utilizing functional endpoints and deployed with DispatcherServlet may be susceptible to a header predicate bypass during pre-flight requests, potentially allowing unauthorized access to resources. Organizations using affected versions of the Spring Framework (5.2.x to 7.0.x) should prioritize this vulnerability to mitigate risks associated with improper request handling and ensure the security of their applications.

CVE
CVE-2026-47892
Severity
CRITICAL
CVSS
9.8
EPSS
0.36%

Original NVD Description

A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.5.RELEASE - 5.2.25.RELEASE

Related CVEs

Other vulnerabilities affecting the same vendor(s)