CVE-2026-59270 – Spring Security

CVSS 9.4 CRITICAL Critical - Same Day Deployment

“Exposed LDAP administration and replayable DPoP proofs can undermine authentication boundaries in affected applications.”

Spring Security is affected by one Critical and one High-severity vulnerability. CVE-2026-59270 affects the embedded UnboundID LDAP server, which registers an administrative credential and binds its listener to all network interfaces. The CVSS score is 9.4, which is Critical severity.

CVE-2026-41707 affects DPoP proof replay protection. Attackers can flood the bounded replay cache, evict valid JWT ID entries, and then replay previously captured DPoP proofs. The CVSS score is 7.4, which is High severity.

Key Details

Affected Product
Vmware Spring Security
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-863
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.