CVE-2026-22754Disclosure(vmware / spring_security)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Vulnerability in Spring Spring Security. If an application uses <sec:intercept-url servlet-path="/servlet-path" pattern="/endpoint/**"/> to define the servlet path for computing a path matcher, then the servlet path is not included and the related authorization rules are not exercised. This can lead to an authorization bypass.This issue affects Spring Security: from 7.0.0 through 7.0.4.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-284CWE-551

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • spring_security

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-04-23); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
spring_security

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-23: 3Mentions · 2026-04-26: 1Mentions · 2026-05-07: 1Technical Details · 2026-04-26: 1Technical Details · 2026-05-07: 104-2304-2605-07
Signal classification2 categories
Disclosure
360.0%
General
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-233
Disclosure1General2
2026-04-261
Disclosure1
2026-05-071
Disclosure1
Full discourse5 posts
  • Cantina 🪐@cantinasecurity
    Disclosure

    If the app falls through to a permissive default when no earlier rule matches, one normal unauthenticated request can reach an endpoint that was supposed to require admin access. That is why this became CVE-2026-22754.

    Post summary

    The entry discloses CVE-2026-22754, a misconfiguration that permits unauthenticated users to access a privileged endpoint, but contains no PoC, exploit code, or patch information.

    10040508
    19.5K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Spring ❗ CVE-2026-22754 ❗ CVE-2026-22753 ❗ CVE-2026-22752 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-spring-4/ https://t.co/cohTXUIqn6

    Post summary

    The post lists three CVEs related to Spring products and links to external resources for additional information, but provides no specific technical, exploit, or patch details.

    00010159
    6.7K followersView on X
  • PinakaHQ@pinakahq
    Disclosure

    CVE-2026-22754: VMware vCenter Server SOAP API Heap Overflow — Pre-Auth RCE — Are You Exposed? https://pinaka.sh/blog/cve-2026-22754-vmware-vcenter-soap-preauth-rce #cybersecurity #attack #vulnearbility #ai #security

    Post summary

    The post announces a pre‑authorization RCE in VMware vCenter’s SOAP API caused by a heap overflow, with no PoC, exploit, active exploitation, or patch discussed.

    0000065
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-22754 Vulnerability in Spring Spring Security. If an application uses  to define the servlet path fo… https://www.cve.org/CVERecord?id=CVE-2026-22754 ----- Traducción: CVE-2026-22754: Vulnerabilidad en Spring Security de Spring. Si una aplicación utiliza pa… http://infoflow.cloud`

    Post summary

    The post merely announces CVE‑2026‑22754, a vulnerability in Spring Security, and links to the CVE record, without providing technical, exploit, or mitigation information.

    0000043
    72 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-22754 Vulnerability in Spring Spring Security. If an application uses &lt;sec:intercept-url servlet-path="/servlet-path" pattern="/endpoint/**"/&gt; to define the servlet path fo… https://www.cve.org/CVERecord?id=CVE-2026-22754

    Post summary

    The text merely references CVE‑2026‑22754 with a brief configuration example and does not provide details on exploitation, patches, or severity.

    00000189
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarespring_security---

Explore more