PT-2026-34250 · Vmware · Spring Security

CVE-2026-22746

·

Published

2026-04-22

·

Updated

2026-07-21

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Spring Security versions 5.7.0 through 5.7.22 Spring Security versions 5.8.0 through 5.8.24 Spring Security versions 6.3.0 through 6.3.15 Spring Security versions 6.5.0 through 6.5.9 Spring Security versions 7.0.0 through 7.0.4
Description An issue exists where the timing attack defense of DaoAuthenticationProvider can be bypassed for users who are disabled, expired, or locked. This occurs if an application utilizes the UserDetails attributes isEnabled, isAccountNonExpired, or isAccountNonLocked to manage user status.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-NW12954
CVE-2026-22746
GHSA-VXF7-QJ7Q-83FH

Affected Products

Spring Security