Warning: Authentication bypass in Spring Security Spring Authorization Server Patch Immediately!
ID: f6a5f810-2706-512a-a79c-9e49b748babb
STIX ID: report--f6a5f810-2706-512a-a79c-9e49b748babb
Feed Name: CCB Advisories Feed
A critical vulnerability (CVE-2026-22752, CVSS 9.6) in Spring Authorization Server (multiple 1.3.x, 1.4.x, 1.5.x and 7.0.x releases) allows an attacker possessing a valid Initial Access Token to register malicious clients via Dynamic Client Registration—potentially leading to Stored XSS, SSRF, privilege escalation, and data breaches; exploitation requires Dynamic Client Registration to be enabled (disabled by default). The advisory recommends urgent patching to fixed versions and increased monitoring/detection to identify related suspicious activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
