Back to Vulnerability Directory
HIGHFixed upstream
CVE-2026-40993
Spring Security SAML 2.0: asserting party credentials deserialized from the database without a filter
Technology
Spring Security
CVSS Score
7.2 / 10.0
Affected Versions
7.0.0 to 7.0.5
Upstream Fix
7.0.6; 7.0.5.1 (Enterprise Support Only)
Published
June 10, 2026
OSSeva Coverage
Fixed upstream
Description
JdbcAssertingPartyMetadataRepository stores verification and encryption credentials as serialized Java objects in the saml2_asserting_party_metadata table. An attacker with write access to that table can store a malicious payload that runs code on the server that reads the rows. VMware scores it 7.3 as the CNA.
Is your Spring Security deployment affected?
If you're running 7.0.0 to 7.0.5, you need this patch. Book a discovery call to get covered.