External risk intelligence

Spring Batch Deserialization Vulnerability Allows Code Execution.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-47875

Spring Batch is typically used as an internal framework for background data processing and job execution. While it operates on network-accessible data, it is rarely deployed as a public-facing service or internet-exposed gateway in common configurations, making direct internet reachability uncommon.

Deserialization

Broadcom Spring Batch

5.2.0 to before 5.2.76.0.0 to before 6.0.4.1

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in how certain applications handle job data could allow attackers to execute arbitrary code. This flaw exists in Spring Batch when processing data from untrusted sources, potentially impacting applications that rely on this component for background tasks and data processing. The main concern at this time is confirming if and where this technology is used within our environment.

  • Malicious code execution in job processing.
  • Confirms relevance and exposure of Spring Batch.
  • Understand exposure; confirm technology usage.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending specially crafted data to an application that uses Spring Batch with an untrusted data source for its job repository. This malicious input targets the Jackson deserialization process within the `Jackson2ExecutionContextStringSerializer`, leading to arbitrary code execution.

  • No special access needed.
  • Malicious input to deserialization.
  • Arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

When applications use Jackson2ExecutionContextStringSerializer with an untrusted job repository, an attacker could execute arbitrary code by providing specially crafted input. This could impact system data, user data, or service behavior.

  • Arbitrary code execution.
  • Malicious input via untrusted data.
  • System compromise and data loss.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects applications using Spring Batch for deserializing execution contexts, particularly those handling untrusted data. Application owners and platform teams are likely responsible for identifying affected systems. The first practical step is to locate all instances of the vulnerable Spring Batch versions, assess their exposure and business criticality, and confirm ownership before planning remediation.

  • App and platform teams should investigate.
  • Verify external data sources for job repositories.
  • Plan remediation based on risk and criticality.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Spring Batch?

Spring Batch is a framework designed for processing large volumes of data in background jobs. It manages tasks like reading, processing, and writing data, often used in enterprise systems to handle scheduled or automated workflows.

What does CVE-2026-47875 mean for my software?

This vulnerability is an instance of CWE-502, Deserialization of Untrusted Data. It means the software can be tricked into executing harmful code if it processes specifically prepared data from an untrusted source, as it fails to properly verify or restrict what it is loading.

How can an attacker trigger this vulnerability?

An attacker needs to provide malicious input to an application that uses Spring Batch with an untrusted job repository. Simply having Spring Batch installed does not trigger the flaw; the application must be configured to deserialize execution contexts from an untrusted source to be susceptible.

Do I need to worry if my Spring Batch app is internal?

Halo Surface Signal notes that Spring Batch is rarely exposed directly to the internet, making it an unlikely target for public-facing attacks. However, you should still care if your internal application processes data that originates from untrusted or external systems.

When should I take action for CVE-2026-47875?

You should begin by identifying if your applications are running the affected versions of Spring Batch. Once identified, prioritize these instances based on whether they handle untrusted data in their job repositories, then work to update the framework to a secure version.

References