Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Patch (application/json-patch+json) requests. Spring Data REST 5.1.0 Spring Data REST 5.0.0 - 5.0.6 Spring Data REST 4.5.0 - 4.5.12 Spring Data REST 4.0.0 - 4.4.15 Spring Data REST 3.7.20 and earlier
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
Spring Data REST versions 3.7.20 and earlier through 5.1.0 fail to properly validate RFC 6902 JSON Patch requests, allowing attackers to mutate protected @Id and @Version properties on entities. This vulnerability is particularly dangerous because identifier and version fields are fundamental to data integrity and access control—modifying them can lead to unauthorized data access, object tampering, privilege escalation, or denial of service. Any organization using affected Spring Data REST versions to expose REST endpoints is vulnerable, especially those handling sensitive data where entity identifiers serve as authorization boundaries.
While this CVE currently lacks mapped MITRE ATT&CK techniques, Casky's AI-driven analysis would detect the attack patterns underlying this vulnerability by examining API request manipulation and data modification behaviors. A practitioner using Casky would identify suspicious JSON Patch payloads attempting to modify @Id/@Version fields through anomalous REST endpoint activity, unauthorized data mutations, and object state changes that violate expected entity immutability. By correlating these behavioral indicators with 754 mapped security skills, Casky would surface exploitation attempts, help teams distinguish legitimate patch operations from malicious ones, and provide context on the data manipulation techniques adversaries use to compromise application data integrity—enabling detection before attackers exploit identifier mutations for lateral movement or privilege escalation.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-47849. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation