Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.6
CVE-2026-22752: Spring Authorization Server can allow login without credentials
CVE-2026-22752 · published 2 months ago
Summary
Versions of Spring Authorization Server from 1.3.0 to 1.5.6 and 7.0.0 to 7.0.4 may let users sign in without proving who they are. This could let attackers gain access to systems that rely on this software for user authentication. Update to the latest released version of Spring Authorization Server as soon as possible.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| spring security | spring authorization server | <= 7.0.4 |
| broadcom | spring_authorization_server |
>= 1.3.0, < 1.3.11 >= 1.4.0, < 1.4.10 >= 1.5.0, < 1.5.7 cpe:2.3:a:broadcom:spring_authorization_server:*:*:*:*:*:*:*:* |
Original advisory text
Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server.
This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through...
Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server.
This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.5.6, from 1.4.0 through 1.4.9, from 1.3.0 through 1.3.10.
This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.5.6, from 1.4.0 through 1.4.9, from 1.3.0 through 1.3.10.
References
- https://spring.io/security/cve-2026-22752 Vendor Advisory
Severity
9.6
Critical
CVSS 3.1: 9.6 (MITRE)
Exploitation
EPSS <1%
Type
CWE-287Improper Authentication
Timeline
Published16 Jul 2026
Updated27 Sep 2026
First seen16 Jul 2026
Track software like this
Free during beta