Is Symantec DLP vulnerable to CVE-2026-41838?
search cancel

Is Symantec DLP vulnerable to CVE-2026-41838?

book

Article ID: 446377

calendar_today

Updated On:

Products

Data Loss Prevention Endpoint Prevent Data Loss Prevention Enforce Data Loss Prevention Enterprise Suite

Issue/Introduction

This article clarifies whether Symantec Data Loss Prevention (DLP) is impacted by the Spring Security vulnerability identified as CVE-2026-41838.

Environment

Symantec DLP16.1, 25.1, 26.1

Cause

NA

Resolution

Symantec Data Loss Prevention is not impacted by CVE-2026-41838.

This vulnerability specifically affects applications that utilize the Spring WebSocket framework. Symantec DLP does not use Spring WebSocket in its architecture; therefore, the vulnerability cannot be exploited within the DLP environment.

Additional Information

https://spring.io/security/cve-2026-41838