top of page
perceptive_background_267k.jpg

In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registratio…

Published:

27 augustus 2026 om 00:00:00

Alert date:

27 augustus 2026 om 16:01:58

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access, Zero-Day Vulnerabilities

CVE-2026-59354 affects Spring Security's OAuth2 Authorization Server module versions 7.0.0 through 7.0.4. The vulnerability is triggered when Dynamic Client Registration is explicitly enabled, causing the registration endpoint to insufficiently validate client metadata fields. An attacker with a valid Initial Access Token can register a malicious client with crafted metadata. Depending on server configuration, this can lead to Stored XSS, Privilege Escalation, or Server-Side Request Forgery (SSRF). The CVSS v3.1 vector indicates network-accessible, low-complexity attack with low privileges required, no user interaction, and high impact on confidentiality and integrity with a changed scope. This makes it a high-severity vulnerability requiring prompt patching or mitigation.

Technical details

Mitigation steps:

Affected products:

Spring Security OAuth2 Authorization Server 7.0.0
Spring Security OAuth2 Authorization Server 7.0.1
Spring Security OAuth2 Authorization Server 7.0.2
Spring Security OAuth2 Authorization Server 7.0.3
Spring Security OAuth2 Authorization Server 7.0.4

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page