CVE-2026-47875

CRITICAL CVSS 3.1: 9.8 EPSS 0.29%
Updated Sep 02, 2026
Spring
Parameter Value
CVSS 9.8 (CRITICAL)
Affected Versions 5.2.0 — 6.0.4.1
Fixed In 5.2.7
Type CWE-502 Deserialization of Untrusted Data, CWE-502 (Deserialization of Untrusted Data)
Vendor Spring
Public PoC No

Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable to a deserialization attack if they use an untrusted data source for the job repository. The JobParameterDeserializer does not properly enforce the trusted-types allowlist, allowing an attacker to craft malicious input that can lead to arbitrary code execution, including known Jackson RCE gadgets. Spring Batch 6.0.0 - 6.0.4 Spring Batch 5.2.0 - 5.2.6

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Vulnerable Products 2

Configuration From (including) Up to (excluding)
Broadcom Spring_Batch
cpe:2.3:a:broadcom:spring_batch:*:*:*:*:*:*:*:*
5.2.0 5.2.7
Broadcom Spring_Batch
cpe:2.3:a:broadcom:spring_batch:*:*:*:*:*:*:*:*
6.0.0 6.0.4.1