CVE-2026-41856

The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue if such annotations are used for authorization decisions. When all conditions are met, security annotations can be ignored at runtime. Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8; 1.0.0 through 1.0.6.
References
Link Resource
https://spring.io/security/cve-2026-41856 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vmware:spring_for_graphql:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_for_graphql:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_for_graphql:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_for_graphql:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-11 07:16

Updated : 2026-07-23 09:10


NVD link : CVE-2026-41856

Mitre link : CVE-2026-41856

CVE.ORG link : CVE-2026-41856


JSON object : View

Products Affected

vmware

  • spring_for_graphql
CWE
CWE-284

Improper Access Control