← Vulnerability feed

Vulnerability record · CVE-2026-47849 · published 27 August 2026

CVE-2026-47849: Vmware spring data rest mass assignment vulnerability

Vmware · Spring Data Rest

Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Patch (application/json-patch+json) requests. Spring Data REST 5.1.0 Spring Data REST 5.0.0 - 5.0.6 Spring Data REST 4.5.0 - 4.5.12 Spring Data REST 4.0.0 - 4.4.15 Spring Data REST 3.7.20 and earlier

7.1 CVSS 3.1 High EPSS 0.35% · top 73.8% CWE-915 · Mass assignment
7.1CVSS 3.1 base score
0.35%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
2 Sep 2026Last modified by NVD

Description

Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Patch (application/json-patch+json) requests. Spring Data REST 5.1.0 Spring Data REST 5.0.0 - 5.0.6 Spring Data REST 4.5.0 - 4.5.12 Spring Data REST 4.0.0 - 4.4.15 Spring Data REST 3.7.20 and earlier

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-47849 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-1273Spring Data Commons property binder allows remote code executionSpring Data Commons fails to properly neutralize special elements in request parameters, allowing crafted input to be bound to object properties. Thi…KEVEPSS 97%analysed9.8CVE-2017-8046Spring Data REST PATCH requests allow remote Java code executionSpring Data REST before 2.6.9 (Ingalls SR9) and before 3.0.1 (Kay SR1), and Spring Boot before 1.5.9 and 2.0 M6, fail to properly validate specially …EPSS 75%analysed8.1CVE-2026-41729Vmware spring data rest expression language injection vulnerabilitySpring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) req…EPSS 0.40%7.5CVE-2026-41728Vmware spring data rest improper access control vulnerabilitySpring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when …EPSS 0.35%7.5CVE-2018-1259Broadcom spring data commons xml external entity (xxe) vulnerabilitySpring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a p…EPSS 4.9%7.5CVE-2018-1274Broadcom spring data commons allocation without limits vulnerabilitySpring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by u…EPSS 1.9%5.3CVE-2026-41730Vmware spring data rest error message information leak vulnerabilitySpring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persistence-layer internals to HTTP …EPSS 0.33%5.3CVE-2026-41837Vmware spring data rest improper access control vulnerabilitySpring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and does not consider Jackson cu…EPSS 0.31%

Source: NIST National Vulnerability Database (record CVE-2026-47849), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.