PT-2026-82413 · Vmware · Spring Security

CVE-2026-59270

·

Published

2026-08-27

·

Updated

2026-08-28

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Spring Security version 7.1.0 Spring Security versions 7.0.0 through 7.0.6 Spring Security versions 6.5.0 through 6.5.11 Spring Security versions 6.4.0 through 6.4.18 Spring Security versions 5.8.0 through 5.8.27 Spring Security versions 5.7.0 through 5.7.25
Description The embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces instead of restricting it to the loopback interface.
Recommendations For version 7.1.0, check listener interfaces and network exposure if the application is exposed to external or untrusted networks. For versions 7.0.0 through 7.0.6, check listener interfaces and network exposure if the application is exposed to external or untrusted networks. For versions 6.5.0 through 6.5.11, check listener interfaces and network exposure if the application is exposed to external or untrusted networks. For versions 6.4.0 through 6.4.18, check listener interfaces and network exposure if the application is exposed to external or untrusted networks. For versions 5.8.0 through 5.8.27, check listener interfaces and network exposure if the application is exposed to external or untrusted networks. For versions 5.7.0 through 5.7.25, check listener interfaces and network exposure if the application is exposed to external or untrusted networks.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59270

Affected Products

Spring Security