Critical Authentication Bypass Vulnerability in Spring Authorization Server
ID: 50e66e36-1e85-50bf-9784-c2cc9fb04b07
STIX ID: report--50e66e36-1e85-50bf-9784-c2cc9fb04b07
Feed Name: ThreatCluster
Threat Score
A critical vulnerability (CVE-2026-22752) was disclosed on July 16, 2026 in Spring Authorization Server affecting versions 1.3.0–1.3.10, 1.4.0–1.4.9, 1.5.0–1.5.6, and 7.0.0–7.0.4. The flaw permits attackers possessing a valid Initial Access Token to perform Dynamic Client Registration with malicious client metadata, potentially leading to stored XSS, privilege escalation, data breaches, and operational downtime; immediate patching and enhanced monitoring are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
