PT-2026-82413 · Vmware · Spring Security
CVE-2026-59270
·
Published
2026-08-27
·
Updated
2026-08-28
CVSS v3.1
9.4
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Spring Security version 7.1.0
Spring Security versions 7.0.0 through 7.0.6
Spring Security versions 6.5.0 through 6.5.11
Spring Security versions 6.4.0 through 6.4.18
Spring Security versions 5.8.0 through 5.8.27
Spring Security versions 5.7.0 through 5.7.25
Description
The embedded UnboundID LDAP server (
UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces instead of restricting it to the loopback interface.Recommendations
For version 7.1.0, check listener interfaces and network exposure if the application is exposed to external or untrusted networks.
For versions 7.0.0 through 7.0.6, check listener interfaces and network exposure if the application is exposed to external or untrusted networks.
For versions 6.5.0 through 6.5.11, check listener interfaces and network exposure if the application is exposed to external or untrusted networks.
For versions 6.4.0 through 6.4.18, check listener interfaces and network exposure if the application is exposed to external or untrusted networks.
For versions 5.8.0 through 5.8.27, check listener interfaces and network exposure if the application is exposed to external or untrusted networks.
For versions 5.7.0 through 5.7.25, check listener interfaces and network exposure if the application is exposed to external or untrusted networks.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spring Security