Skip to content
Cve 2026 59270

Cve 2026 59270

spring.io August 24, 2026

Spring Security's embedded UnboundID LDAP server ( UnboundIdContainer ) unconditionally registers an administrative credential and binds its listener to all available network interfaces.

An attacker who could reach the LDAP listener port could authenticate using the well-known administrative bind DN, and then read or modify entries in the in-memory directory.

No further mitigation steps are necessary.

To report a security vulnerability for a project within the Spring portfolio, see the Security Policy

Tanzu Spring offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Check out all the upcoming events in the Spring community.

Extracted Entities