Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-59270: Spring Security may expose admin LDAP credentials on network

CVE-2026-59270 · published 1 month ago
Summary

Versions of Spring Security that include the embedded UnboundID LDAP server automatically create a default admin account and listen on every network interface. This can let anyone on the network connect to the LDAP service and gain administrative access. Update to a fixed version or disable the embedded LDAP server if it is not needed.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
spring spring security 7.1.0
vmware spring_security >= 5.7.0, < 5.7.26
>= 5.8.0, < 5.8.28
>= 6.4.0, < 6.4.19
>= 6.5.0, < 6.5.12
>= 7.0.0, < 7.0.6.1
>= 7.1.0, < 7.1.0.1
cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:*
Original advisory text
Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces. Spring Secur...
Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces.
Spring Security 7.1.0
Spring Security 7.0.0 - 7.0.6
Spring Security 6.5.0 - 6.5.11
Spring Security 6.4.0 - 6.4.18
Spring Security 5.8.0 - 5.8.27
Spring Security 5.7.0 - 5.7.25
References
Severity
9.1 Critical
CVSS 3.1: 9.4 (MITRE)
Exploitation
EPSS <1%
Type
CWE-798Use of Hard-coded Credentials
CWE-863Incorrect Authorization
Timeline
Published27 Aug 2026
Updated27 Sep 2026
First seen27 Aug 2026
Sources
CVE-2026-59270 · MITRE
Track software like this
Free during beta