Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-59270

Spring Security: embedded UnboundID LDAP server exposes a well-known admin bind DN on all interfaces

Technology

Spring Security

CVSS Score

9.1 / 10.0

Affected Versions

5.7.0 to 5.7.25; 5.8.0 to 5.8.27; 6.4.0 to 6.4.18; 6.5.0 to 6.5.11; 7.0.0 to 7.0.6; 7.1.0

Upstream Fix

7.0.7; 7.1.1; 7.0.6.1, 7.1.0.1, 6.5.12, 6.4.19, 5.8.28, 5.7.26 (Enterprise Support Only)

Published

August 27, 2026

OSSeva Coverage

Fixed upstream

Description

Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) always registers an administrative credential and binds its listener to every network interface. An attacker who can reach the LDAP port can authenticate with the well-known administrative bind DN and read or modify the in-memory directory. It applies when UnboundIdContainer is configured directly or through Spring Boot's spring.ldap.embedded properties and the port is not restricted to localhost. VMware scores it 9.4 as the CNA.

Upstream record: NVD · CVE.org

Is your Spring Security deployment affected?

If you're running 5.7.0 to 5.7.25; 5.8.0 to 5.8.27; 6.4.0 to 6.4.18; 6.5.0 to 6.5.11; 7.0.0 to 7.0.6; 7.1.0, you need this patch. Book a discovery call to get covered.