


Perceptive Security
SOC/SIEM Consultancy

In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registratio…
Published:
27 augustus 2026 om 00:00:00
Alert date:
27 augustus 2026 om 16:01:58
Source:
nvd.nist.gov
Web Technologies, Identity & Access, Zero-Day Vulnerabilities
CVE-2026-59354 affects Spring Security's OAuth2 Authorization Server module versions 7.0.0 through 7.0.4. The vulnerability is triggered when Dynamic Client Registration is explicitly enabled, causing the registration endpoint to insufficiently validate client metadata fields. An attacker with a valid Initial Access Token can register a malicious client with crafted metadata. Depending on server configuration, this can lead to Stored XSS, Privilege Escalation, or Server-Side Request Forgery (SSRF). The CVSS v3.1 vector indicates network-accessible, low-complexity attack with low privileges required, no user interaction, and high impact on confidentiality and integrity with a changed scope. This makes it a high-severity vulnerability requiring prompt patching or mitigation.
Technical details
Mitigation steps:
Affected products:
Spring Security OAuth2 Authorization Server 7.0.0
Spring Security OAuth2 Authorization Server 7.0.1
Spring Security OAuth2 Authorization Server 7.0.2
Spring Security OAuth2 Authorization Server 7.0.3
Spring Security OAuth2 Authorization Server 7.0.4
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-59354
https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N&version=3.1
https://spring.io/security/cve-2026-59354
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
