CVE-2026-59293
6.6
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Summary
Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate down to SMB1/CIFS, which lacks mandatory signing/encryption and is vulnerable to NTLM relay and content-tampering MITM. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Spring | Spring Integration | 7.1.0 | affected |
| Spring | Spring Integration | 7.0.0 <= 7.0.5 | affected |
| Spring | Spring Integration | 6.5.0 <= 6.5.10 | affected |
| Spring | Spring Integration | 6.4.0 <= 6.4.12 | affected |
Weaknesses
- CWE-757 Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.