Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.8

CVE-2026-59354: Spring Security 7.0.0‑7.0.4 lets attackers register harmful apps

CVE-2026-59354 · published 1 month ago
Summary

Versions 7.0.0 through 7.0.4 of Spring Security’s online‑login authorization server allow a client to be added without proper checks when the dynamic registration feature is turned on. An attacker who already has a special credential issued by the server can create a client that carries malicious data, which can cause unwanted code to run in users’ browsers, give the attacker higher privileges, or make the server contact external sites without permission. Apply the update released after 7.0.4 or turn off dynamic client registration until the update can be applied.

What to do
  • Update vmware spring_security to version 7.0.5 or later.
Affected software
VendorProductAffected versions
vmware by broadcom spring security (oauth2 authorization server module) <= 7.0.4
vmware spring_security >= 7.0.0, < 7.0.5
cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:*
Original advisory text
In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient vali...
In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation of certain client metadata fields supplied by the registering client. An attacker who possesses a valid Initial Access Token can register a malicious client with crafted metadata, which, depending on server configuration and how the metadata is later rendered or used, may result in Stored Cross-Site Scripting (XSS), Privilege Escalation, or Server-Side Request Forgery (SSRF).
Severity
8.8 High
CVSS 3.1: 6.1 (NVD)
Exploitation
EPSS <1%
Type
CWE-20Improper Input Validation
Timeline
Published27 Aug 2026
Updated27 Sep 2026
First seen27 Aug 2026
Sources
CVE-2026-59354 · MITRE
Track software like this
Free during beta