logo

Critical Authentication Bypass Vulnerability in Spring Authorization Server

ID: 50e66e36-1e85-50bf-9784-c2cc9fb04b07

STIX ID: report--50e66e36-1e85-50bf-9784-c2cc9fb04b07

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-07-18

Date Updated: 2026-07-20

...
...

A critical vulnerability (CVE-2026-22752) was disclosed on July 16, 2026 in Spring Authorization Server affecting versions 1.3.0–1.3.10, 1.4.0–1.4.9, 1.5.0–1.5.6, and 7.0.0–7.0.4. The flaw permits attackers possessing a valid Initial Access Token to perform Dynamic Client Registration with malicious client metadata, potentially leading to stored XSS, privilege escalation, data breaches, and operational downtime; immediate patching and enhanced monitoring are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.