Junglewise Threat Intelligence

CVE-2026-47877: Spring Security Authorization Server XSS in default consent page

CVE-2026-47877 · Severity: high · CVSS 8.2 · Published 2026-08-27

Vendors: Spring.

Executive brief

Spring Security Authorization Server's default consent page fails to encode user-controlled input, allowing attackers to inject malicious HTML or JavaScript. An attacker could craft a malicious authorization request that injects code into the consent page shown to users, potentially stealing credentials, session tokens, or triggering unwanted actions. This affects the identity and access management layer used by many enterprise applications.

Technical details

The vulnerability is a reflected cross-site scripting (XSS) flaw in Spring Security Authorization Server's default consent page template. User-controlled values from authorization request parameters are rendered in HTML without proper entity encoding, allowing attackers to inject arbitrary HTML/JavaScript. The attack vector is network-based and requires no authentication; an attacker crafts a malicious authorization URL and tricks a user into visiting it. Successful exploitation allows arbitrary code execution in the user's browser within the context of the Authorization Server, potentially compromising OAuth/OIDC flows. Patches are available in Spring Security 7.0.7 and 7.1.1 and later.

Affected products

  • Spring Security Authorization Server 7.0.0 through 7.0.6, 7.1.0

Timeline

  • 2026-08-27: disclosed

References