CVE-2026-22730Disclosure(vmware / spring_ai)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch vmware spring_ai systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and execute arbitrary SQL commands. The vulnerability exists due to missing input sanitization.

4.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-89

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • spring_ai

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 23 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 21 signals
  • Disclosure: 12 classified signals
  • General: 8 classified signals
  • Peaked 5d ago at 7 mentions (2026-03-18); latest day: 1
  • 23 total mentions across 7 days

Affected systems

Vendors
Products
spring_ai

Deep dive

Activity timeline23 mentions / 7d
02457Mentions · 2026-03-17: 3Mentions · 2026-03-18: 7Mentions · 2026-03-19: 6Mentions · 2026-03-23: 2Mentions · 2026-03-27: 1Mentions · 2026-03-28: 3Mentions · 2026-04-10: 1PoC Mentioned / Linked · 2026-03-23: 1Exploit Tool / Code · 2026-03-23: 1Patch / Workaround · 2026-03-17: 1Patch / Workaround · 2026-03-23: 1Technical Details · 2026-03-17: 3Technical Details · 2026-03-18: 7Technical Details · 2026-03-19: 5Technical Details · 2026-03-23: 2Technical Details · 2026-03-27: 1Technical Details · 2026-03-28: 2Technical Details · 2026-04-10: 103-1703-1803-1903-2303-2703-2804-10
Signal classification4 categories
Disclosure
1252.2%
General
834.8%
Patch
28.7%
PoC
14.3%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-03-173
Disclosure2Patch1
2026-03-187
Disclosure5General2
2026-03-196
Disclosure5General1
2026-03-232
Patch1PoC1
2026-03-271
General1
2026-03-283
General3
2026-04-101
General1
Full discourse20 posts
  • Nicolas Krassas@Dinosn
    Disclosure

    CVE-2026-22730: SQL Injection in Spring AI’s MariaDB Vector Store https://blog.securelayer7.net/cve-2026-22730-sql-injection-spring-ai-mariadb/

    Post summary

    The tweet announces CVE‑2026‑22730, an SQL Injection flaw in Spring AI’s MariaDB Vector Store, and links to a blog post that presumably contains further details.

    030721.1K
    153.3K followersView on X
  • /r/netsec@_r_netsec
    Disclosure

    CVE-2026-22730: SQL Injection in Spring AI’s MariaDB Vector Store https://blog.securelayer7.net/cve-2026-22730-sql-injection-spring-ai-mariadb/

    Post summary

    The post announces CVE‑2026‑22730, a SQL injection vulnerability affecting Spring AI’s MariaDB Vector Store, linking to a blog article for more details.

    04010530
    32.9K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Two critical flaws in Spring AI (CVE-2026-22729 & CVE-2026-22730) allow attackers to bypass access controls via JSONPath and SQL injection. Update now. #SpringAI #CVE #CyberSecurity #InfoSec #SQLInjection #JavaSecurity #Vulnerability #AppSec #TechNews https://securityonline.info/critical-spring-ai-vulnerabilities-sql-jsonpath-injection-cve-2026-22730/ https://t.co/KU01zxmHHi

    Post summary

    Two critical Spring AI flaws (CVE‑2026‑22729 and CVE‑2026‑22730) allow bypass of access controls through JSONPath and SQL injection; the text stresses that users should update immediately to mitigate the risk.

    02021376
    10.7K followersView on X
  • dbugs@ptdbugs
    PoC

    🔔 A PoC/exploit has been discovered for vulnerability CVE-2026-22730 Vendor: VMware Product: Spring AI Description: A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and execute arbitrary SQL commands. The vulnerability exists due to missing input sanitization. Link: https://github.com/NULL200OK/CVE-2026-22730-Scanner #dbugs_vuln

    Post summary

    A proof‑of‑concept and exploit scanner for CVE‑2026‑22730, a critical SQL injection in VMware Spring AI, has been released, but no active exploitation or patch information is currently available.

    00002307
    733 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『The deeper reason it went unnoticed: the SQL in `MariaDBVectorStore .java` does use `?` placeholders — for the embedding vector and distance threshold.』 CVE-2026-22730: SQL Injection in Spring AI’s MariaDB Vector Store https://blog.securelayer7.net/cve-2026-22730-sql-injection-spring-ai-mariadb/

    Post summary

    The blog post announces a SQL Injection vulnerability (CVE‑2026‑22730) in Spring AI’s MariaDB Vector Store, detailing how the query uses placeholders but providing no PoC, exploit code, or patch information.

    00011393
    6.7K followersView on X
  • Abcas MCP Guard@abcas_mcp_guard
    General

    Spring AI users: CVE-2026-22729 (JSONPath Injection) and CVE-2026-22730 (SQL Injection) highlight that even "safe" frameworks need runtime monitoring. 🛡️ Don't trust inputs blindly. Secure your agentic workflows with MCP Guard. #MCPSecurity #SpringAI #AISecurity

    Post summary

    The message references two newly identified CVEs in Spring AI (JSONPath and SQL injection) and advises caution, but provides no additional technical details, exploits, or mitigation guidance.

    0001046
    11 followersView on X
  • z3n@zench4n
    General

    Consider the implications of CVE-2026-22730 in Spring AI. A SQLi in a vector store directly impacts an agent's knowledge base. A deep dive asks: how does this compromise affect agent autonomy, data integrity, and downstream decisions? Beyond the immediate exploit.

    Post summary

    The post mentions a SQL injection (CVE-2026-22730) in Spring AI’s vector store but offers no details on exploitation, patches, or PoC, merely raising high-level concerns about its impact on agent autonomy and data integrity.

    1000028
    1.4K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    Java Spring AIにSQLインジェクションとJSONPathインジェクションの脆弱性(CVE-2026-22730、CVE-2026-22729) https://rocket-boys.co.jp/security-measures-lab/spring-ai-sql-injection-jsonpath-injection-cve-2026-22730-cve-2026-22729/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The post announces new SQL injection and JSONPath injection vulnerabilities in Java Spring AI (CVE-2026-22730 & CVE-2026-22729).

    00010166
    337 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-22730 - High A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and execute arbitrary SQL commands. The vulne... https://www.thehackerwire.com/vulnerability/CVE-2026-22730/ https://t.co/XXtIaExcH8

    Post summary

    The post announces a critical SQL injection in Spring AI’s MariaDBFilterExpressionConverter that permits bypassing access controls to run arbitrary SQL, but it provides no PoC, exploit, or patch details.

    0001040
    138 followersView on X
  • dbugs@ptdbugs
    Disclosure

    CVE-2026-22730: SQL Injection in Spring AI MariaDBFilterExpressionConverter CVE: CVE-2026-22730 PT-Identifier: PT-2026-25940 Vendor: Vmware Product: Spring AI CVSS: 8.8 Credits: n/a Description: A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and execute arbitrary SQL commands. The vulnerability exists due to missing input sanitization. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-22730 • https://spring.io/security/cve-2026-22730 #dbugs_vuln

    Post summary

    The announcement details CVE‑2026‑22730 as a critical SQL injection flaw in Spring AI’s MariaDBFilterExpressionConverter, noting missing input sanitization and a CVSS score of 8.8.

    0001078
    633 followersView on X
  • z3n@zench4n
    General

    It's about anticipating emergent behaviors and adversarial prompting, not just patching known flaws. The `CVE-2026-22730` scanner for Spring AI is a step, but the agent's reasoning process is the next frontier.

    Post summary

    The text merely references CVE‑2026‑22730 as part of a scanner for Spring AI, without offering any technical, exploit, patch, or exploitation details.

    0000039
    1.4K followersView on X
  • z3n@zench4n
    General

    Tools like RTOSploit (Indspl0it/RTOSploit) are gaining traction, reflecting increased focus on embedded security. Meanwhile, CVE-2026-22730-Scanner points to persistent SQLi risks in AI frameworks like Spring AI. Stay vigilant.

    Post summary

    The text points out general cybersecurity trends and mentions an SQLi vulnerability in a Spring AI framework, but lacks specific exploitation, patch, or PoC details.

    0000023
    1.4K followersView on X
  • z3n@zench4n
    General

    Tools like RTOSploit (Indspl0it/RTOSploit) are gaining traction, reflecting increased focus on embedded security. Meanwhile, CVE-2026-22730-Scanner points to persistent SQLi risks in AI frameworks like Spring AI. Stay vigilant.

    Post summary

    The post highlights the growing use of RTOSploit and a scanner pointing to persistent SQL injection risks in AI frameworks, but provides no evidence of active exploitation or mitigation efforts.

    000008
    1.4K followersView on X
  • Prabhat Kashyap | prabhat.dev@prabhatdotdev
    Patch

    Spring AI just got hit with 2 critical CVEs (CVE-2026-22729, CVE-2026-22730). Injection flaws in filter expressions can bypass metadata-based access control in vector stores meaning cross-tenant data exposure. If you’re using spring-ai-vector-store or mariadb-store with user filters, you’re at risk. 👉 Upgrade immediately: 1.0.4 / 1.1.3 #AI #SpringBoot #CyberSecurity #RAG #LLM #DevSecOps

    Post summary

    Spring AI disclosed two critical injection‑based CVEs that allow cross‑tenant data exposure, and it urges users to update to version 1.0.4 or 1.1.3 to remediate.

    0000032
    8 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en productos Spring ❗ CVE-2026-22730 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-spring-2/ https://t.co/s9i6z6j3yd

    Post summary

    The tweet lists CVE‑2026‑22730 affecting Spring products and links to external sources for more information, but provides no further details.

    0000082
    6.6K followersView on X
  • Security Harvester@secharvesterx
    Disclosure

    CVE-2026-22730: SQL Injection in Spring AI’s MariaDB Vector Store https://blog.securelayer7.net/cve-2026-22730-sql-injection-spring-ai-mariadb/ https://t.co/u8SOGbOtLB

    Post summary

    The tweet announces a new SQL injection vulnerability (CVE‑2026‑22730) in Spring AI’s MariaDB Vector Store and directs readers to a blog for more details.

    0000099
    793 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22730 A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and execute arbitrary… https://www.cve.org/CVERecord?id=CVE-2026-22730

    Post summary

    The post announces a critical SQL injection flaw in Spring AI's MariaDBFilterExpressionConverter that lets attackers bypass metadata controls and run arbitrary code; no PoC, exploit, or patch details are provided.

    00000150
    56.8K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    ⚠️ CVE-2026-22730: CVE... MariaDB filter bypass in Spring AI's metadata controls = instant database takeover with low-priv creds, CVSS 8.8 screams patch now #SQLi #SpringAI. https://zerodaysignal.com/vulnerability/CVE-2026-22730 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE‑2026‑22730 describes a MariaDB filter bypass that can lead to database takeover with low‑privilege credentials; it is presented as a newly disclosed vulnerability (SQLi, CVSS 8.8) with an urgent call for patching.

    0000063
    155 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-22730 SQL Injection in Spring AI MariaDBFilterExpressionConverter Bypassing Access Controls https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-22730

    Post summary

    CVE-2026-22730 is a SQL Injection in Spring AI’s MariaDBFilterExpressionConverter that can bypass access controls; no evidence of exploitation, PoC, or patches is provided.

    0000039
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-22730 - CVE-2026-22730: SQL Injection in Spring AI MariaDBFilterExpressionConverter Intel Report: https://ift.tt/GBF4zdU

    Post summary

    The notice identifies CVE-2026-22730 as a SQL‑injection flaw in the Spring AI MariaDBFilterExpressionConverter, citing an Intel report for more details.

    0000023
    335 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarespring_ai---

Explore more