Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-47841

Spring Security WebAuthn: user verification skipped with a distributed session store

Technology

Spring Security

CVSS Score

7.4 / 10.0

Affected Versions

6.4.0 to 6.4.18; 6.5.0 to 6.5.11; 7.0.0 to 7.0.6; 7.1.0

Upstream Fix

7.0.7; 7.1.1; 7.0.6.1, 7.1.0.1, 6.5.12, 6.4.19 (Enterprise Support Only)

Published

August 26, 2026

OSSeva Coverage

Fixed upstream

Description

Spring Security compares UserVerificationRequirement by identity. After an HTTP session is serialized and deserialized, as with Spring Session on Redis, JDBC or Hazelcast, the comparison with REQUIRED fails and user verification is silently disabled. An attacker holding a user's authenticator could complete WebAuthn authentication without the PIN or biometric step. Only applications that explicitly require user verification are affected. The 7.4 score is VMware's as the CNA.

Upstream record: NVD · CVE.org

Is your Spring Security deployment affected?

If you're running 6.4.0 to 6.4.18; 6.5.0 to 6.5.11; 7.0.0 to 7.0.6; 7.1.0, you need this patch. Book a discovery call to get covered.