CVE-2026-59270 – Spring Security
CVSS 9.4
CRITICAL
Critical - Same Day Deployment
“Exposed LDAP administration and replayable DPoP proofs can undermine authentication boundaries in affected applications.”
Spring Security is affected by one Critical and one High-severity vulnerability. CVE-2026-59270 affects the embedded UnboundID LDAP server, which registers an administrative credential and binds its listener to all network interfaces. The CVSS score is 9.4, which is Critical severity.
CVE-2026-41707 affects DPoP proof replay protection. Attackers can flood the bounded replay cache, evict valid JWT ID entries, and then replay previously captured DPoP proofs. The CVSS score is 7.4, which is High severity.
Key Details
- Affected Product
- Vmware Spring Security
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-863
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.