Executive brief
Spring Authorization Server, a framework used to implement OAuth2 and OpenID Connect authentication, contains a vulnerability that allows attackers to bypass security checks. This could allow an unauthorized user to gain access to protected resources or impersonate other users. Organizations using this library to manage user logins and permissions should update to a patched version immediately to prevent unauthorized access to sensitive data.
Technical details
An authentication bypass vulnerability exists in Spring Security Spring Authorization Server due to a 'primary weakness' in its security logic. The flaw allows a remote attacker with low privileges to bypass authentication mechanisms and potentially gain elevated access to protected resources. The vulnerability is reachable over the network and does not require user interaction. Affected versions include the 7.0.x, 1.5.x, 1.4.x, and 1.3.x branches. Users are advised to upgrade to the latest patched releases within their respective version streams.
Affected products
- Spring Security Spring Authorization Server 7.0.0 through 7.0.4, 1.5.0 through 1.5.6, 1.4.0 through 1.4.9, 1.3.0 through 1.3.10
Timeline
- 2026-07-16: disclosed: CVE published to NVD dataset