CVE-2026-59293CWE-757

CVE-2026-59293

Medium · published August 28, 2026

CVSS v3.1
6.6
EPSS
0%
Percentile
12.6
In the wild
Unconfirmed
What it is

Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate down to SMB1/CIFS, which lacks mandatory signing/encryption and is vulnerable to NTLM relay and content-tampering MITM.

Spring Integration 7.1.0

Spring Integration 7.0.0 - 7.0.5

Spring Integration 6.5.0 - 6.5.10

Spring Integration 6.4.0 - 6.4.12

The record
Technical detail
CVSS v3.1
6.6 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00221 · 12.6th percentile
Weakness
CWE-757 · Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')
Published
2026-08-28T00:17Z
Affected products (4)
ProductVersionsFixed in
vmware/spring_integration≥ 6.4.0, < 6.4.136.4.13
vmware/spring_integration≥ 6.5.0, < 6.5.116.5.11
vmware/spring_integration≥ 7.0.0, < 7.0.5.17.0.5.1
vmware/spring_integration≥ 7.1.0, < 7.1.0.17.1.0.1
References (1)
EPSS history
Timeline
  • 27 AUG 17:57Z
    SMB minimum protocol dialect defaults to SMB1
    cvelistv5