Junglewise Threat Intelligence

CVE-2026-59318: Spring AI tool calling privilege escalation

CVE-2026-59318 · Severity: medium · CVSS 6.5 · Published 2026-08-21

Technologies: VMware Spring Ai. Vendors: VMware.

Executive brief

Spring AI, a framework for building AI-powered applications, has a flaw in how it enforces which tools (functions) are available to AI models in a given request. This allows an AI model to invoke tools that were not supposed to be available, potentially leading to privilege escalation and unauthorized access to sensitive functionality.

Technical details

In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is dispatched. Under certain conditions, a tool that was not made available to the current request could be invoked. This is a tool access control bypass vulnerability in the request handling layer. The vulnerability affects versions 1.0.0–1.0.9, 1.1.0–1.1.8, and 2.0.0. No evidence of active exploitation in the wild has been reported. Patches are expected from the Spring project.

Affected products

  • VMware Spring AI 1.0.0 through 1.0.9, 1.1.0 through 1.1.8, 2.0.0

Timeline

  • 2026-08-21: disclosed

References

Related threats