Critical Authentication Bypass Vulnerability in Spring Authorization Server

Critical Authentication Bypass Vulnerability in Spring Authorization Server

First seen 19 Jul 2026, 08:42 UTC Ccb.Belgium.Bespring.io 85% similarity 72.6

Article Content

Browse articles
ThreatCluster

A critical vulnerability, CVE-2026-22752, has been identified in Spring Authorization Server, affecting versions 1.3.0 to 1.3.10, 1.4.0 to 1.4.9, 1.5.0 to 1.5.6, and 7.0.0 to 7.0.4. The flaw allows attackers with a valid Initial Access Token to register malicious clients through Dynamic Client Registration, potentially leading to serious impacts such as data breaches and operational downtime. This vulnerability arises from insufficient validation of client metadata fields, enabling unauthorized actions like Stored Cross-Site Scripting (XSS) and Privilege Escalation. Organizations are urged to patch affected systems immediately and enhance monitoring capabilities to detect suspicious activities. The vulnerability was disclosed on July 16, 2026, and is considered critical due to its potential for exploitation.

Key Points: • CVE-2026-22752 allows attackers to exploit Spring Authorization Server. • Affected versions include 1.3.0 to 1.3.10, 1.4.0 to 1.4.9, 1.5.0 to 1.5.6, and 7.0.0 to 7.0.4. • Immediate patching and enhanced monitoring are recommended for organizations.

ThreatCluster AI

Timeline

2026-07-16
CVE-2026-22752 published
A critical vulnerability in Spring Authorization Server was disclosed, allowing exploitation via Initial Access Tokens.
spring.io
2026-07-17
CCB issues urgent advisory
The Centre for Cybersecurity Belgium recommended immediate patching for affected Spring Authorization Server versions.
Ccb.Belgium.Be
2026-07-18
Spring.io confirms vulnerability details
Spring.io provided further details on the vulnerability, emphasizing the need for immediate action by users of the affected software.
spring.io

Community

Browse all →