Back to Vulnerability Directory
HIGHFixed upstream
CVE-2026-22747
Spring Security: SubjectX500PrincipalExtractor misreads malformed certificate CNs
Technology
Spring Security
CVSS Score
8.1 / 10.0
Affected Versions
7.0.0 to 7.0.4
Upstream Fix
7.0.5
Published
April 22, 2026
OSSeva Coverage
Fixed upstream
Description
SubjectX500PrincipalExtractor does not correctly handle some malformed X.509 certificate CN values and can read the wrong username, so a carefully crafted certificate can impersonate another user. The advisory describes the fix as defence in depth, since the component sits behind pre-authentication that trusts an upstream validator. VMware scores it 6.8 as the CNA.
Is your Spring Security deployment affected?
If you're running 7.0.0 to 7.0.4, you need this patch. Book a discovery call to get covered.