CVE-2026-59318: Incorrect Authorization in Spring Spring AI
Description
CVE-2026-59318 is an authorization vulnerability in Spring AI's tool calling support. The vulnerability arises because the per-request tool list, which is advertised to the model as a boundary, is not fully enforced when dispatching a tool call. This can allow a tool that was not made available to the current request to be invoked, potentially leading to privilege escalation. The issue affects multiple versions of Spring AI, including 1.0.0 through 1.0.9, 1.1.0 through 1.1.8, and version 2.0.0.
CVSS v3.1
Score 6.5medium
Affected software
Spring
Spring AI
pkg:maven/org.springframework/spring-aiRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In Spring AI's tool calling feature, the per-request tool list is intended to restrict which tools the model can invoke. However, this boundary is not fully enforced during tool call dispatch. As a result, under certain conditions, a tool not authorized for the current request can be invoked. This incorrect authorization can lead to privilege escalation. The vulnerability affects Spring AI versions 1.0.0 through 1.0.9, 1.1.0 through 1.1.8, and 2.0.0. The CVSS 3.1 score is 6.5 (medium severity), reflecting network attack vector, high attack complexity, low privileges required, user interaction required, scope changed, high confidentiality impact, low integrity impact, and no availability impact.
Potential Impact
An attacker able to trigger tool calls in Spring AI could invoke tools not authorized for the current request. This can lead to privilege escalation, potentially exposing sensitive information or allowing unauthorized actions. The confidentiality impact is high, while integrity impact is low and availability is not affected.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch links are provided in the available data. Until a patch is available, users should review and restrict tool call permissions carefully and monitor for unusual tool invocation behavior.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- vmware
- Date Reserved
- 2026-07-04T18:13:57.026Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a884318acd9273b491e875a
Added to database: 08/21/2026, 12:22:48 UTC
Last enriched: 09/11/2026, 02:48:30 UTC
Last updated: 10/05/2026, 06:48:17 UTC
Views: 117
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.