CVE-2026-41839: Spring Framework Escalation via Session Fixation in WebFlux
A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerable to an escalation attack exchanging a known session ID for that of an authenticated user.
Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Spring Frameworkto a version that resolves this vulnerability.Fixed in 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41839?
CVE-2026-41839 has a medium severity rating of 4.2.
How do I fix CVE-2026-41839?
To fix CVE-2026-41839, upgrade your Spring Framework to version 7.0.8 or later, or to 6.2.19 or later.
What applications are affected by CVE-2026-41839?
CVE-2026-41839 affects WebFlux applications using Spring Framework versions 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, and earlier versions.
What vulnerability category does CVE-2026-41839 fall under?
CVE-2026-41839 falls under the category of escalation attacks associated with session fixation.
What is the main risk associated with CVE-2026-41839?
The main risk of CVE-2026-41839 is that a compromised subdomain can allow an attacker to exchange a known session ID for that of an authenticated user.