CVE-2026-22752: Spring Security Authorization Server Dynamic Client Registration endpoints perform insufficient validation of client metadata
Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server.
This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.5.6, from 1.4.0 through 1.4.9, from 1.3.0 through 1.3.10.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22752?
CVE-2026-22752 has a critical severity score of 9.6.
How do I fix CVE-2026-22752?
To mitigate CVE-2026-22752, upgrade to Spring Authorization Server version 7.0.5 or higher, or 1.5.7 or higher.
Which versions of Spring Authorization Server are affected by CVE-2026-22752?
CVE-2026-22752 affects Spring Authorization Server versions 7.0.0 to 7.0.4, 1.5.0 to 1.5.6, 1.4.0 to 1.4.9, and 1.3.0 to 1.3.10.
What type of vulnerability is CVE-2026-22752?
CVE-2026-22752 is an authentication bypass vulnerability due to insufficient validation of client metadata.
What is the impact of CVE-2026-22752?
Exploitation of CVE-2026-22752 can lead to unauthorized access to resources that should be protected.