CVE-2026-41694: VMware Spring Security
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature, attackers may be able to craft these SAML payloads and use the Service Provider as a decryption oracle. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5.
Affected products
- VMware Spring Security: from 5.7.0, before 5.7.24 (fixed in 5.7.24); from 5.8.0, before 5.8.26 (fixed in 5.8.26); from 6.3.0, before 6.3.17 (fixed in 6.3.17); from 6.4.0, before 6.4.17 (fixed in 6.4.17); from 6.5.0, before 6.5.10.2 (fixed in 6.5.10.2); from 7.0.0, before 7.0.5.1 (fixed in 7.0.5.1)
Published 2026-06-10. Last modified 2026-07-23.