Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-59354

Spring Security Authorization Server: dynamic client registration accepts crafted client metadata

Technology

Spring Security

CVSS Score

8.8 / 10.0

Affected Versions

7.0.0 to 7.0.4

Upstream Fix

7.0.5

Published

August 27, 2026

OSSeva Coverage

Fixed upstream

Description

When dynamic client registration is explicitly enabled in Spring Security's OAuth2 Authorization Server module, the registration endpoint does not validate some client metadata fields sufficiently. An attacker with a valid initial access token can register a client whose metadata leads to stored cross-site scripting, privilege escalation or server-side request forgery, depending on configuration. VMware scores it 9.6 as the CNA.

Upstream record: NVD · CVE.org

Is your Spring Security deployment affected?

If you're running 7.0.0 to 7.0.4, you need this patch. Book a discovery call to get covered.