PatchSiren cyber security CVE debrief
CVE-2026-47880 Spring CVE debrief
A vulnerability in Spring Integration allows a producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component to set String JMS properties that are copied verbatim into the Spring Integration MessageHeaders. This issue affects various versions of Spring Integration, including 7.1.0, 7.0.0 - 7.0.5, 6.5.0 - 6.5.10, 6.4.0 - 6.4.12, and 5.5.21 and earlier. The vulnerability can be exploited by setting properties such as replyChannel, errorChannel, or json__TypeId__, potentially affecting the security of affected deployments.
- Vendor
- Spring
- Product
- Spring Integration
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-27
- Original CVE updated
- 2026-09-10
- Advisory published
- 2026-08-27
- Advisory updated
- 2026-09-10
Who should care
Defenders responsible for Spring Integration deployments, especially those using JMS inbound components, should assess exposure and prioritize verification and remediation efforts.
Why it matters
A vulnerability in Spring Integration allows a producer to set String JMS properties that are copied into the Spring Integration MessageHeaders, potentially affecting the security of affected deployments.
- Defenders need to verify exposure in their Spring Integration deployments.
- Remediation requires updating to patched versions of Spring Integration.
- Monitoring for suspicious activity in affected environments is necessary.
- Exposure verification and remediation should be prioritized for deployments using JMS inbound components.
Technical summary
A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component can set String JMS properties named replyChannel, errorChannel, or json__TypeId__ which are copied verbatim into the Spring Integration MessageHeaders. This issue affects Spring Integration versions 7.1.0, 7.0.0 - 7.0.5, 6.5.0 - 6.5.10, 6.4.0 - 6.4.12, and 5.5.21 and earlier. The vulnerability can be exploited by setting these properties, potentially affecting the security of affected deployments. Defenders should prioritize verifying exposure in their Spring Integration deployments, especially those using JMS inbound components.
Defensive priority
Defenders should prioritize verifying exposure in their Spring Integration deployments, especially those using JMS inbound components.
Recommended defensive actions
- Verify Spring Integration deployments for exposure, especially those using JMS inbound components.
- Check version numbers and apply patches according to vendor advisories.
- Monitor for suspicious activity in Spring Integration environments.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but the scope of affected deployments and specific remediation steps require verification from official sources. Affected deployments should be verified, especially those using JMS inbound components, and defenders should prioritize patching to mitigate potential risks. The issue requires careful review of Spring Integration configurations and JMS properties to ensure security.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-47880 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-47880
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-47880 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47880
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://spring.io/security/cve-2026-47880
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.