Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to remote code execution inside the application JVM. Affected versions: Spring Statemachine 4.0.0 through 4.0.1 Spring Statemachine 3.2.0 through 3.2.4
References
History

Wed, 24 Jun 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Spring
Spring spring Statemachine
Vendors & Products Spring
Spring spring Statemachine

Wed, 24 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 24 Jun 2026 09:45:00 +0000

Type Values Removed Values Added
Title Deserialization Without Class Allowlist in Spring Statemachine Enables Remote Code Execution

Wed, 24 Jun 2026 07:00:00 +0000

Type Values Removed Values Added
Title Deserialization Without Class Allowlist in Spring Statemachine Enables Remote Code Execution

Wed, 24 Jun 2026 03:45:00 +0000

Type Values Removed Values Added
Title Unrestricted Deserialization in Spring Statemachine Persistence Backends

Wed, 24 Jun 2026 00:00:00 +0000

Type Values Removed Values Added
Title Unrestricted Deserialization in Spring Statemachine Persistence Backends

Tue, 23 Jun 2026 21:15:00 +0000

Type Values Removed Values Added
Description Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to remote code execution inside the application JVM. Affected versions: Spring Statemachine 4.0.0 through 4.0.1 Spring Statemachine 3.2.0 through 3.2.4
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published: 2026-06-23T20:59:02.378Z

Updated: 2026-06-24T15:24:46.354Z

Reserved: 2026-04-22T06:22:10.082Z

Link: CVE-2026-41862

cve-icon Vulnrichment

Updated: 2026-06-24T15:24:30.233Z

cve-icon NVD

No data.

cve-icon Redhat

No data.