spring.io
Critical Authentication Bypass Vulnerability in Spring Authorization Server
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical vulnerability, CVE-2026-22752, has been identified in Spring Authorization Server, affecting versions 1.3.0 to 1.3.10, 1.4.0 to 1.4.9, 1.5.0 to 1.5.6, and 7.0.0 to 7.0.4. The flaw allows attackers with a valid Initial Access Token to register malicious clients through Dynamic Client Registration, potentially leading to serious impacts such as data breaches and operational downtime. This vulnerability arises from insufficient validation of client metadata fields, enabling unauthorized actions like Stored Cross-Site Scripting (XSS) and Privilege Escalation. Organizations are urged to patch affected systems immediately and enhance monitoring capabilities to detect suspicious activities. The vulnerability was disclosed on July 16, 2026, and is considered critical due to its potential for exploitation.
Key Points: • CVE-2026-22752 allows attackers to exploit Spring Authorization Server. • Affected versions include 1.3.0 to 1.3.10, 1.4.0 to 1.4.9, 1.5.0 to 1.5.6, and 7.0.0 to 7.0.4. • Immediate patching and enhanced monitoring are recommended for organizations.