Spring Security OAuth2 Authorization Server: Insufficient validation of Dynamic Client Registration metadata
Summary
| CVE | CVE-2026-59354 |
|---|---|
| State | PUBLISHED |
| Assigner | vmware |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-27 10:16:36 UTC |
| Updated | 2026-08-28 18:47:30 UTC |
| Description | In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation of certain client metadata fields supplied by the registering client. An attacker who possesses a valid Initial Access Token can register a malicious client with crafted metadata, which, depending on server configuration and how the metadata is later rendered or used, may result in Stored Cross-Site Scripting (XSS), Privilege Escalation, or Server-Side Request Forgery (SSRF). |
Risk And Classification
Primary CVSS: v3.1 9.6 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
EPSS: 0.003730000 probability, percentile 0.301620000 (date 2026-08-29)
Problem Types: CWE-20 | CWE-20 CWE-20: Improper Input Validation
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 9.6 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
| 3.1 | CNA | CVSS | 9.6 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
HighAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | VMware By Broadcom | Spring Security OAuth2 Authorization Server Module | affected 7.0.0 7.0.4 semver | Not specified |
| CNA | VMware By Broadcom | Spring Security OAuth2 Authorization Server Module | unaffected 7.0.5 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| spring.io/security/cve-2026-59354 | [email protected] | spring.io | |
| nvd.nist.gov/vuln-metrics/cvss/v3-calculator | [email protected] | nvd.nist.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Kelvin Mbogo (@addcontent) (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2026-04-21T00:00:00.000Z | Public disclosure and fix released (Spring Security 7.0.5). |
Solutions
CNA: Upgrade to Spring Security 7.0.5 or later.
There are currently no legacy QID mappings associated with this CVE.