PT-2026-34250 · Vmware · Spring Security

Published

2026-04-22

·

Updated

2026-04-23

·

CVE-2026-22746

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Spring Security versions 5.7.0 through 5.7.22 Spring Security versions 5.8.0 through 5.8.24 Spring Security versions 6.3.0 through 6.3.15 Spring Security versions 6.5.0 through 6.5.9 Spring Security versions 7.0.0 through 7.0.4
Description An issue exists where the timing attack defense of DaoAuthenticationProvider can be bypassed for users who are disabled, expired, or locked. This occurs if an application utilizes the UserDetails attributes isEnabled, isAccountNonExpired, or isAccountNonLocked to manage user status.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-22746
GHSA-VXF7-QJ7Q-83FH

Affected Products

Spring Security