CVE-2026-59354
Spring Security Authorization Server: dynamic client registration accepts crafted client metadata
Technology
Spring Security
CVSS Score
8.8 / 10.0
Affected Versions
7.0.0 to 7.0.4
Upstream Fix
7.0.5
Published
August 27, 2026
OSSeva Coverage
Fixed upstream
Description
When dynamic client registration is explicitly enabled in Spring Security's OAuth2 Authorization Server module, the registration endpoint does not validate some client metadata fields sufficiently. An attacker with a valid initial access token can register a client whose metadata leads to stored cross-site scripting, privilege escalation or server-side request forgery, depending on configuration. VMware scores it 9.6 as the CNA.
Is your Spring Security deployment affected?
If you're running 7.0.0 to 7.0.4, you need this patch. Book a discovery call to get covered.