GHSA-j7j9-5253-f7vh
CRITICALCVE-2026-42555Multiple classes evaluate Spring Expression Language (SpEL) expressions from user-supplied input using StandardEvaluationContext, which provides unrestricted access to Java types and methods. An authenticated user with the ADMIN role can achieve Remote Code Execution and credential exfiltration.
- Affected
- >= 12.0.0, < 12.32.0
- Fixed in
- 12.32.0
- Weakness
- CWE-94
- Published
- 2026-05-06
- Source
- github