CVE-2026-2742Disclosure(vaadin / vaadin)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An authentication bypass vulnerability exists in Vaadin 14.0.0 through 14.14.0, 23.0.0 through 23.6.6, 24.0.0 through 24.9.7 and 25.0.0 through 25.0.1, applications using Spring Security due to inconsistent path pattern matching of reserved framework paths. Accessing the /VAADIN endpoint without a trailing slash bypasses security filters, and allowing unauthenticated users to trigger framework initialization and create sessions without proper authorization. Users of affected versions using Spring Security should upgrade as follows: 14.0.0-14.14.0 upgrade to 14.14.1, 23.0.0-23.6.6 to 23.6.7, 24.0.0 - 24.9.7 to 24.9.8, and 25.0.0-25.0.1 upgrade to 25.0.2 or newer. Please note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 14, 23, 24, 25 version.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vaadin

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-19); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
vaadin

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-10: 1Mentions · 2026-03-19: 2Mentions · 2026-05-27: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-19: 2Technical Details · 2026-05-27: 103-1003-1905-27
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-101
Disclosure1
2026-03-192
Disclosure2
2026-05-271
General1
Full discourse4 posts
  • HackingHub@hackinghub_io
    General

    Vaadin treats the request as a framework request, triggers initialization, and creates a session without proper authorization. This is CVE-2026-2742: unauthorized session creation via reserved framework path access.

    Post summary

    The post merely states that CVE-2026-2742 involves unauthorized session creation via a reserved framework path, with no further detail on exploits, patches, or active usage.

    10001266
    12.6K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-2742 An authentication bypass vulnerability exists in Vaadin 14.0.0 through 14.14.0, 23.0.0 through 23.6.6, 24.0.0 through 24.9.7 and 25.0.0 through 25.0.1, applications usi… https://www.cve.org/CVERecord?id=CVE-2026-2742 ----- Traducción: CVE-2026-2742 Exi… http://infoflow.cloud`

    Post summary

    A concise disclosure of CVE‑2026‑2742, describing an authentication bypass in multiple Vaadin releases and linking to the CVE record.

    0000036
    61 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2742 An authentication bypass vulnerability exists in Vaadin 14.0.0 through 14.14.0, 23.0.0 through 23.6.6, 24.0.0 through 24.9.7 and 25.0.0 through 25.0.1, applications usi… https://www.cve.org/CVERecord?id=CVE-2026-2742

    Post summary

    The note announces CVE-2026-2742 as an authentication bypass in certain Vaadin releases, without providing PoC, exploit code, patches, or evidence of active exploitation.

    00000216
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-2742 - "Vaadin Spring Security Trailing Slash Authentication Bypass" Intel Report: https://ift.tt/a0g7DbI

    Post summary

    A new vulnerability, CVE-2026-2742, is disclosed in Vaadin Spring Security, enabling authentication bypass due to a trailing slash handling issue, as reported by an intelligence analysis.

    0000031
    345 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvaadinvaadin---

Explore more