CVE-2026-59293
Received Received - Intake

SMB1/CIFS Downgrade Vulnerability in Spring Integration

Vulnerability report for CVE-2026-59293, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-27

Last updated on: 2026-08-27

Assigner: VMware

Description

Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate down to SMB1/CIFS, which lacks mandatory signing/encryption and is vulnerable to NTLM relay and content-tampering MITM. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-27
Last Modified
2026-08-27
Generated
2026-08-28
AI Q&A
2026-08-27
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
spring integration 7.1.0
spring integration From 7.0.0 (inc) to 7.0.5 (inc)
spring integration From 6.5.0 (inc) to 6.5.10 (inc)
spring integration From 6.4.0 (inc) to 6.4.12 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-59293 is a medium-severity vulnerability in Spring Integration where the jCIFS client defaults to the outdated SMB1/CIFS protocol if the application does not explicitly set the minimum SMB version. SMB1 lacks mandatory signing and encryption, making it vulnerable to NTLM relay attacks and man-in-the-middle (MITM) threats.

Impact Analysis

An attacker on the same network could downgrade the protocol, intercept or alter file transfers, or capture NTLM credentials. This could lead to unauthorized access, data breaches, or manipulation of sensitive information during file transfers.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Non-compliance risks include legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Upgrade affected Spring Integration versions to fixed releases: 7.1.1 (OSS) or 7.1.0.1 (Enterprise), 7.0.6 (OSS) or 7.0.5.1 (Enterprise), 6.5.11 (Enterprise), or 6.4.13 (Enterprise). No additional mitigation is required after upgrading.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59293. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart