CVE-2026-47841
Spring Security WebAuthn: user verification skipped with a distributed session store
Technology
Spring Security
CVSS Score
7.4 / 10.0
Affected Versions
6.4.0 to 6.4.18; 6.5.0 to 6.5.11; 7.0.0 to 7.0.6; 7.1.0
Upstream Fix
7.0.7; 7.1.1; 7.0.6.1, 7.1.0.1, 6.5.12, 6.4.19 (Enterprise Support Only)
Published
August 26, 2026
OSSeva Coverage
Fixed upstream
Description
Spring Security compares UserVerificationRequirement by identity. After an HTTP session is serialized and deserialized, as with Spring Session on Redis, JDBC or Hazelcast, the comparison with REQUIRED fails and user verification is silently disabled. An attacker holding a user's authenticator could complete WebAuthn authentication without the PIN or biometric step. Only applications that explicitly require user verification are affected. The 7.4 score is VMware's as the CNA.
Is your Spring Security deployment affected?
If you're running 6.4.0 to 6.4.18; 6.5.0 to 6.5.11; 7.0.0 to 7.0.6; 7.1.0, you need this patch. Book a discovery call to get covered.