Is Endpoint Protection Manager impacted by the Spring Security Vulnerability CVE-2026-22732
search cancel

Is Endpoint Protection Manager impacted by the Spring Security Vulnerability CVE-2026-22732

book

Article ID: 440831

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

Need to know whether Symantec Endpoint Protection Manager or Client [ SEPM/SEP] is affected by the recently disclosed Forced Browsing vulnerability (CVE-2026-22732) in Spring Security
refer: https://nvd.nist.gov/vuln/detail/CVE-2026-22732 

Environment

Symantec Endpoint Protection Manager  14.3.x, 14.4.x

Resolution

According to the security advisory https://nvd.nist.gov/vuln/detail/CVE-2026-22732 this issue affects Spring Security Servlet applications using lazy writing of HTTP headers in versions 5.7.0 through 5.7.21, 5.8.0 through 5.8.23, 6.3.0 through 6.3.14, 6.4.0 through 6.4.14, 6.5.0 through 6.5.8, and 7.0.0 through 7.0.3.
SEPM does not use the vulnerable version of the Spring Security