CVE-2026-47835
Received Received - Intake
BaseFortify

Publication date: 2026-06-15

Last updated on: 2026-06-15

Assigner: VMware

Description
In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire VectorDB. Affected components: spring-ai-elasticsearch-store, spring-ai-opensearch-store, spring-ai-gemfire-store. Affected versions: Spring AI 1.0.0 through 1.0.x (fix 1.0.9). Spring AI 1.1.0 through 1.1.x (fix 1.1.8).
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-15
Last Modified
2026-06-15
Generated
2026-06-16
AI Q&A
2026-06-15
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 8 associated CPEs
Vendor Product Version / Range
spring_ai spring_ai_elasticsearch_store *
spring_ai spring_ai_opensearch_store *
spring_ai spring_ai_gemfire_store *
spring_ai spring_ai From 1.0.0 (inc) to 1.0.9 (inc)
spring_ai spring_ai From 1.1.0 (inc) to 1.1.8 (inc)
elasticsearch elasticsearch *
opensearch opensearch *
gemfire gemfire *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-943 The product generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2026-47835 is a security vulnerability in Spring AI Vector Stores versions 1.0.0 through 1.0.x and 1.1.0 through 1.1.x. It allows attackers to use special characters to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire VectorDB components.

The affected components include spring-ai-elasticsearch-store, spring-ai-opensearch-store, and spring-ai-gemfire-store.

Impact Analysis

This vulnerability has a high severity CVSS score of 8.6 and can impact the confidentiality, integrity, and availability of your systems.

  • Confidentiality: Unauthorized access to sensitive data via arbitrary query execution.
  • Integrity: Potential manipulation or corruption of data through crafted queries.
  • Availability: Possible disruption or denial of service caused by malicious queries.
Mitigation Strategies

To mitigate this vulnerability, users should upgrade the affected Spring AI Vector Stores components to the fixed versions: 1.0.9 for the 1.0.x series and 1.1.8 for the 1.1.x series.

No additional mitigation steps are required beyond upgrading.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47835. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart