PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-47880 Spring CVE debrief

A vulnerability in Spring Integration allows a producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component to set String JMS properties that are copied verbatim into the Spring Integration MessageHeaders. This issue affects various versions of Spring Integration, including 7.1.0, 7.0.0 - 7.0.5, 6.5.0 - 6.5.10, 6.4.0 - 6.4.12, and 5.5.21 and earlier. The vulnerability can be exploited by setting properties such as replyChannel, errorChannel, or json__TypeId__, potentially affecting the security of affected deployments.

Vendor
Spring
Product
Spring Integration
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-27
Original CVE updated
2026-09-10
Advisory published
2026-08-27
Advisory updated
2026-09-10

Who should care

Defenders responsible for Spring Integration deployments, especially those using JMS inbound components, should assess exposure and prioritize verification and remediation efforts.

Why it matters

A vulnerability in Spring Integration allows a producer to set String JMS properties that are copied into the Spring Integration MessageHeaders, potentially affecting the security of affected deployments.

  • Defenders need to verify exposure in their Spring Integration deployments.
  • Remediation requires updating to patched versions of Spring Integration.
  • Monitoring for suspicious activity in affected environments is necessary.
  • Exposure verification and remediation should be prioritized for deployments using JMS inbound components.

Technical summary

A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component can set String JMS properties named replyChannel, errorChannel, or json__TypeId__ which are copied verbatim into the Spring Integration MessageHeaders. This issue affects Spring Integration versions 7.1.0, 7.0.0 - 7.0.5, 6.5.0 - 6.5.10, 6.4.0 - 6.4.12, and 5.5.21 and earlier. The vulnerability can be exploited by setting these properties, potentially affecting the security of affected deployments. Defenders should prioritize verifying exposure in their Spring Integration deployments, especially those using JMS inbound components.

Defensive priority

Defenders should prioritize verifying exposure in their Spring Integration deployments, especially those using JMS inbound components.

Recommended defensive actions

  • Verify Spring Integration deployments for exposure, especially those using JMS inbound components.
  • Check version numbers and apply patches according to vendor advisories.
  • Monitor for suspicious activity in Spring Integration environments.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but the scope of affected deployments and specific remediation steps require verification from official sources. Affected deployments should be verified, especially those using JMS inbound components, and defenders should prioritize patching to mitigate potential risks. The issue requires careful review of Spring Integration configurations and JMS properties to ensure security.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-47880 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-47880

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-47880 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47880

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.