Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-40993

Spring Security SAML 2.0: asserting party credentials deserialized from the database without a filter

Technology

Spring Security

CVSS Score

7.2 / 10.0

Affected Versions

7.0.0 to 7.0.5

Upstream Fix

7.0.6; 7.0.5.1 (Enterprise Support Only)

Published

June 10, 2026

OSSeva Coverage

Fixed upstream

Description

JdbcAssertingPartyMetadataRepository stores verification and encryption credentials as serialized Java objects in the saml2_asserting_party_metadata table. An attacker with write access to that table can store a malicious payload that runs code on the server that reads the rows. VMware scores it 7.3 as the CNA.

Upstream record: NVD · CVE.org

Is your Spring Security deployment affected?

If you're running 7.0.0 to 7.0.5, you need this patch. Book a discovery call to get covered.