CVE-2026-22752Disclosure(broadcom / spring_authorization_server)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch broadcom spring_authorization_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.5.6, from 1.4.0 through 1.4.9, from 1.3.0 through 1.3.10.

0.8/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • spring_authorization_server

Threat summary

  • Patch or workaround signal is available
  • 13 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 9 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-06-07); latest day: 1
  • 13 total mentions across 8 days

Affected systems

Vendors
Products
spring_authorization_server

Deep dive

Activity timeline13 mentions / 8d
01223Mentions · 2026-04-22: 2Mentions · 2026-04-23: 2Mentions · 2026-04-26: 2Mentions · 2026-04-29: 1Mentions · 2026-04-30: 1Mentions · 2026-06-07: 3Mentions · 2026-07-16: 1Mentions · 2026-07-17: 1Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-04-23: 1Patch / Workaround · 2026-04-26: 1Patch / Workaround · 2026-04-29: 1Patch / Workaround · 2026-06-07: 2Patch / Workaround · 2026-07-17: 1Technical Details · 2026-04-22: 2Technical Details · 2026-04-23: 1Technical Details · 2026-04-26: 2Technical Details · 2026-04-29: 1Technical Details · 2026-06-07: 1Technical Details · 2026-07-16: 1Technical Details · 2026-07-17: 104-2204-2304-2604-2904-3006-0707-1607-17
Signal classification3 categories
Disclosure
646.2%
Patch
646.2%
General
17.7%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-04-222
Disclosure1Patch1
2026-04-232
Disclosure1Patch1
2026-04-262
Disclosure1Patch1
2026-04-291
Patch1
2026-04-301
General1
2026-06-073
Disclosure1Patch2
2026-07-161
Disclosure1
2026-07-171
Disclosure1
Full discourse13 posts
  • yousukezan@yousukezan
    Patch

    Spring Securityに複数の脆弱性が判明し、認証回避や権限昇格につながる恐れがある。特に最新の7.0系はほぼ全ての新規問題の影響を受け、緊急対応が求められている。 最も深刻なのはCVE-2026-22752で、CVSS 9.6の重大な問題だ。Authorization Serverで動的クライアント登録を有効にした場合、メタデータ検証不備により悪意あるクライアント登録が可能となり、設定次第でXSSやSSRF、権限昇格に発展する。またCVE-2026-22754およびCVE-2026-22753ではパス判定不備により認可バイパスが発生する。さらにCVE-2026-22747では証明書のCN処理不備によりユーザーなりすましが可能となり、CVE-2026-22746では認証状態の推測が可能となる。加えてCVE-2026-22751のワンタイムトークン競合やCVE-2026-22748のJWT設定不備も確認された。 対策として7.0.5、6.5.10、6.4.16への更新が推奨され、暫定的にはURLパターンの明示などで回避可能だが恒久対応にはアップデートが不可欠である。 https://securityonline.info/spring-security-7-0-vulnerabilities-authorization-bypass-cve-2026-22752/

    Post summary

    The post outlines several high‑severity CVEs in Spring Security 7.0, provides detailed technical information, and stresses the urgency of updating to specified patch releases, offering a temporary URL‑pattern workaround but no evidence of active exploitation.

    000421.2K
    14.4K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 CVE-2026-22752 (Spring Security) Critical flaw in Authorization Server → XSS, SSRF & privilege escalation risks Attackers with a valid token can register malicious clients and compromise auth flows Patch ASAP

    Post summary

    Spring Security’s Authorization Server has a critical flaw that can lead to XSS, SSRF, and privilege escalation by allowing attackers with a valid token to register malicious clients; urgent patches are required.

    00040101
    44 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical #AuthenticationBypass in #Spring Authorization Server Dynamic Client Registration! #CVE-2026-22752 CVSS: 9.6. Can lead to Stored #XSS, Privilege Escalation & #SSRF! Read our advisory at https://ccb.belgium.be/advisories/warning-authentication-bypass-spring-security-spring-authorization-server-patch and #Patch #Patch #Patch

    Post summary

    This post announces a critical authentication bypass in Spring Authorization Server (CVE‑2026‑22752) capable of triggering XSS, privilege escalation, and SSRF, and links to an advisory that includes patch information.

    01000347
    7.2K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Sources Spring Security Advisory CVE-2026-22752: HeroDevs Deep Dive: "CVE-2026-22752: Spring Authorization Server Critical — XSS, SSRF, and Privilege Escalation" (May 6, 2026) Cibersafety Analysis: CVE-2026-22752 in Spring (May…

    Post summary

    The advisory and accompanying analyses disclose that CVE‑2026‑22752 is a critical flaw in Spring Authorization Server, affecting XSS, SSRF, and privilege escalation, but provide no PoC, exploit code, or evidence of active exploitation.

    1000030
    253 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    On April 21, 2026, Spring released Spring Authorization Server 1.5.7 and Spring Security 7.0.5 containing fixes for CVE-2026-22752. On May 6, HeroDevs published a deep technical analysis revealing the scope of the impact. The vulnerability lies in the Dynamic Client…

    Post summary

    Spring Security released a patch for CVE-2026-22752, and HeroDevs published a technical analysis of its impact. No PoC, exploit, or evidence of active exploitation is mentioned.

    1000027
    253 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    The Forgotten Gateway: Spring Authorization Server CVE-2026-22752 Turns OAuth Into an Escalation Engine. On April 21, 2026, Spring released Spring Authorization Server 1.5.7 and Spring Security 7.0.5 containing fixes for CVE-2026-22752.

    Post summary

    The text announces that Spring released updated versions 1.5.7 and 7.0.5 to fix CVE-2026-22752.

    1000024
    253 followersView on X
  • iototsecnews@iototsecnews
    Patch

    Spring Security Authorization Server の脆弱性 CVE-2026-22752 が FIX:XSS/SSRF/権限昇格のリスク https://iototsecnews.jp/2026/04/22/critical-spring-authorization-server-issue-exposes-systems-to-xss-and-ssrf-attacks/ Spring Authorization Server の特定の機能において、外部から送られてくるデータのチェックが不十分だったことで、脆弱性 CVE-2026-22752 が発生しています。特にクライアントを動的に登録する仕組みを利用している場合に、悪意の情報を正しく制限できなかったことが問題となっています。ユーザーが入力するデータだけではなく、システム間でやり取りされるメタデータに対しても、常に厳格な検証を行うことが大切です。認証の基盤となるサーバを守ることは、システム全体の安全を守ることにつながります。まずはご自身の環境を確認し、修正バージョンへのアップデートを検討してみてください。ご利用のチームは、ご注意ください。 #CVE202622752 #SpringSecurityAuthorizationServer #Vulnerability

    Post summary

    The article alerts about CVE‑2026‑22752, a Spring Authorization Server flaw enabling XSS, SSRF, and privilege escalation, and urges users to update to the patched version.

    01000122
    485 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Spring ❗ CVE-2026-22754 ❗ CVE-2026-22753 ❗ CVE-2026-22752 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-spring-4/ https://t.co/cohTXUIqn6

    Post summary

    The tweet announces three newer Spring product vulnerabilities (CVE‑2026‑22754, 22753, 22752) and links to a CERT page for further information.

    00010159
    6.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22752 Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 th… https://www.cve.org/CVERecord?id=CVE-2026-22752

    Post summary

    The text announces the CVE‑2026‑22752 authentication‑bypass vulnerability affecting Spring Authorization Server.

    00000617
    57.8K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-22752: Spring Security Authorization Server Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04d-G0j0

    Post summary

    The text is the headline of an article announcing CVE-2026-22752 in Spring Security Authorization Server, with no specific technical details, exploit information, or mitigation steps provided.

    0000018
    29 followersView on X
  • cybersecuritypath@cybrsecpath
    Disclosure

    CVE-2026-22752: Critical Spring Security Flaw Allows XSS & SSRF https://thecybrdef.com/cve-2026-22752-spring-security-xss-ssrf-vulnerability/ #CVE202622752 #SpringSecurity #CyberSecurity

    Post summary

    The brief notice announces CVE-2026-22752 as a critical Spring Security vulnerability that permits XSS and SSRF attacks.

    0000042
    7 followersView on X
  • CyberTech Insights@CyberTech_In
    Patch

    Critical flaw (CVE-2026-22752) in Spring Authorization Server enables XSS, SSRF, and privilege escalation. Patch immediately or disable Dynamic Client Registration to reduce risk. 𝐑𝐞𝐚𝐝 𝐟𝐮𝐥𝐥 𝐬𝐭𝐨𝐫𝐲 : https://cybertechnologyinsights.com/cybersecurity/critical-spring-auth-server-flaw-enables-xss-and-ssrf/ https://t.co/7iaT403BAk

    Post summary

    A new flaw CVE-2026-22752 in Spring Authorization Server permits XSS, SSRF, and privilege escalation, and users are advised to apply the patch or disable Dynamic Client Registration to mitigate the risk.

    0000041
    19 followersView on X
  • cybersecuritypath@cybrsecpath
    Disclosure

    CVE-2026-22752: Critical Spring Security Flaw Allows XSS & SSRF https://thecybrdef.com/cve-2026-22752-spring-security-xss-ssrf-vulnerability/ #CVE202622752 #SpringSecurity #CyberSecurity

    Post summary

    A new critical vulnerability in Spring Security (CVE-2026-22752) that enables cross‑site scripting and server‑side request forgery has been publicly identified.

    0000072
    6 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbroadcomspring_authorization_server---

Explore more