CVE-2026-40966: VectorStoreChatMemoryAdvisor conversation scoping can lead to cross-tenant memory exfiltration
In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histories, including secrets and credentials, by injecting filter logic through conversationId. Only applications that use VectorStoreChatMemoryAdvisor and pass user-supplied input as a conversationId are affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40966?
CVE-2026-40966 is considered a high-severity vulnerability due to potential exposure of sensitive user data.
How do I fix CVE-2026-40966?
To fix CVE-2026-40966, apply the latest security patches provided by VMware for Spring AI (VectorStoreChatMemoryAdvisor).
What are the potential impacts of CVE-2026-40966?
CVE-2026-40966 can lead to cross-tenant memory exfiltration, allowing attackers to access chat histories, secrets, and credentials from other users.
Who is affected by CVE-2026-40966?
CVE-2026-40966 affects users of VMware Spring AI (VectorStoreChatMemoryAdvisor) who rely on its chat memory functionalities.
Is CVE-2026-40966 related to conversation security?
Yes, CVE-2026-40966 directly impacts conversation security by enabling attackers to bypass isolation mechanisms.