CVE-2026-59270
Spring Security: embedded UnboundID LDAP server exposes a well-known admin bind DN on all interfaces
Technology
Spring Security
CVSS Score
9.1 / 10.0
Affected Versions
5.7.0 to 5.7.25; 5.8.0 to 5.8.27; 6.4.0 to 6.4.18; 6.5.0 to 6.5.11; 7.0.0 to 7.0.6; 7.1.0
Upstream Fix
7.0.7; 7.1.1; 7.0.6.1, 7.1.0.1, 6.5.12, 6.4.19, 5.8.28, 5.7.26 (Enterprise Support Only)
Published
August 27, 2026
OSSeva Coverage
Fixed upstream
Description
Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) always registers an administrative credential and binds its listener to every network interface. An attacker who can reach the LDAP port can authenticate with the well-known administrative bind DN and read or modify the in-memory directory. It applies when UnboundIdContainer is configured directly or through Spring Boot's spring.ldap.embedded properties and the port is not restricted to localhost. VMware scores it 9.4 as the CNA.
Is your Spring Security deployment affected?
If you're running 5.7.0 to 5.7.25; 5.8.0 to 5.8.27; 6.4.0 to 6.4.18; 6.5.0 to 6.5.11; 7.0.0 to 7.0.6; 7.1.0, you need this patch. Book a discovery call to get covered.