A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input is not sanitized.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HVMware Spring Data Mongodb
APPVmware3.4.0≤ 3.3.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2026-41717HIGH8.1same product
Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability. The issue...
CVE-2026-41696MEDIUM5.9same product
Metody zapytań repozytorium Spring Data MongoDB opatrzone adnotacją @Query wykorzystujące wiązanie parametrów ...
CVE-2026-59310CRITICAL9.8⚠ KEVPL ✓same vendor
VMware vCenter: path traversal w Syslog umożliwia RCE
CVE-2025-22224CRITICAL9.3⚠ KEVPL ✓same vendor
VMware ESXi/Workstation: TOCTOU umożliwia ucieczkę z VM przez VMX process
CVE-2024-38812CRITICAL9.8⚠ KEVPL ✓same vendor
VMware vCenter Server — heap-overflow w DCERPC umożliwia RCE