CVE-2026-40993
published 2026-06-10CVE-2026-40993: An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_asserting_party_metadata) may be able to store…
PriorityP345high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.20%
9.8th percentile
An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_asserting_party_metadata) may be able to store malicious serialized payloads in the columns containing the collection of verification or encryption credentials (verification_credentials and encryption_credentials, respectively).
Affected versions:
Spring Security 7.0.0 through 7.0.5.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring | spring_security | >= 7.0.0 < 7.0.5.1 | 7.0.5.1 |
| vmware | spring_security | >= 7.0.0 < 7.0.5.1 | 7.0.5.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Vmware Spring Security up to 7.0.5 Database Table JdbcAssertingPartyMetadataRepository saml2_asserting_party_metadata deserialization (CNNVD-202606-2876)
vuldb·2026-06-28·CVSS 7.2
CVE-2026-40993 [HIGH] Vmware Spring Security up to 7.0.5 Database Table JdbcAssertingPartyMetadataRepository saml2_asserting_party_metadata deserialization (CNNVD-202606-2876)
A vulnerability was found in Vmware Spring Security up to 7.0.5 and classified as problematic. This vulnerability affects the function JdbcAssertingPartyMetadataRepository of the component Database Table Handler. Such manipulation of the argument saml2_asserting_party_metadata leads to deserialization.
This vulnerability is referenced as CVE-2026-40993. The attack needs to be initiated within the local network. No exploit is available.
It is suggested to upgrade the affected component.
GHSA
An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_asserting_party_metadata) may be able to store malicious serialized payloads in the colu
ghsa_unreviewed·2026-06-10
CVE-2026-40993 [HIGH] CWE-502 An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_asserting_party_metadata) may be able to store malicious serialized payloads in the colu
An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_asserting_party_metadata) may be able to store malicious serialized payloads in the columns containing the collection of verification or encryption credentials (verification_credentials and encryption_credentials, respectively).
Affected versions:
Spring Security 7.0.0 through 7.0.5.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-10
Published