← All Advisories

CVE-2026-41862

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-41862

Key Details

CVECVE-2026-41862
CVSS Score / Version8.8 (High) / CVSS v3.1
Updated2026-09-22
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsBroadcom spring_statemachine
Classified asCWE-502 (Deserialization of Untrusted Data)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Broadcomspring_statemachine
SubsystemsGeneral OT
SectorsMultiple

What to Know

Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to remote code execution inside the application JVM.

Affected versions:

Spring Statemachine 4.0.0 through 4.0.1

Spring Statemachine 3.2.0 through 3.2.4

What to Do

Monitor Broadcom's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-41862
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-41862
Vendor advisoryhttps://spring.io/security/cve-2026-41862