CVE-2026-41846 | Vmware Spring Framework up to 5.3.48/6.1.27/6.2.18/7.0.7 JSP Form Tag cssClass/cssErrorClass/cssStyle cross site scripting
A vulnerability categorized as problematic has been discovered in Vmware Spring Framework up to 5.3.48/6.1.27/6.2.18/7.0.7. Affected is an unknown function of the component JSP Form Tag Handler. Executing a manipulation of the argument cssClass/cssErrorClass/cssStyle can lead to cross site scripting.
This vulnerability is tracked as CVE-2026-41846. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.