PT-2026-82396 · Vmware · Spring Security

·

CVE-2026-47877

·

Published

2026-08-27

·

Updated

2026-08-27

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Spring Security versions 7.0.0 through 7.0.6 Spring Security version 7.1.0
Description The default consent page of the Spring Security Authorization Server renders user-controlled values without applying HTML entity encoding. This lack of encoding can lead to the execution of malicious scripts in the user's browser.
Recommendations Update Spring Security versions 7.0.0 through 7.0.6 to a patched version. Update Spring Security version 7.1.0 to a patched version.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47877

Affected Products

Spring Security