CVE-2026-22752

Source
https://cve.org/CVERecord?id=CVE-2026-22752
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22752.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-22752
Downstream
Published
2026-07-16T08:40:23Z
Modified
2026-09-06T03:46:17Z
Severity
  • 9.6 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N CVSS Calculator
Summary
Spring Security Authorization Server Dynamic Client Registration endpoints perform insufficient validation of client metadata
Details

Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server.

This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.5.6, from 1.4.0 through 1.4.9, from 1.3.0 through 1.3.10.

Database specific
{
    "cna_assigner": "vmware",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22752.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "7.0.0"
                },
                {
                    "last_affected": "7.0.4"
                },
                {
                    "introduced": "1.5.0"
                },
                {
                    "last_affected": "1.5.6"
                },
                {
                    "introduced": "1.4.0"
                },
                {
                    "last_affected": "1.4.9"
                },
                {
                    "introduced": "1.3.0"
                },
                {
                    "last_affected": "1.3.10"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "introduced": "7.0.0"
                },
                {
                    "fixed": "7.0.4"
                },
                {
                    "introduced": "1.5.0"
                },
                {
                    "fixed": "1.5.6"
                },
                {
                    "introduced": "1.4.0"
                },
                {
                    "fixed": "1.4.9"
                },
                {
                    "introduced": "1.3.0"
                },
                {
                    "fixed": "1.3.10"
                }
            ],
            "source": "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / github.com/spring-attic/spring-authorization-server

Affected ranges

Type
GIT
Repo
https://github.com/spring-attic/spring-authorization-server
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:broadcom:spring_authorization_server:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.5.0"
        },
        {
            "fixed": "1.5.7"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

1.*
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22752.json"