CVE-2026-47878 | Spring Batch up to 5.2.6/6.0.4 DefaultExecutionContextSerializer ObjectInputStream.readObject deserialization

SecurityVulns

A vulnerability, which was classified as critical, was found in Spring Batch up to 5.2.6/6.0.4. This affects the function ObjectInputStream.readObject of the component DefaultExecutionContextSerializer. The manipulation results in deserialization.

This vulnerability is known as CVE-2026-47878. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More