PT-2026-34251 · Vmware · Spring Security

Published

2026-04-22

·

Updated

2026-04-23

·

CVE-2026-22747

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Spring Spring Security versions 7.0.0 through 7.0.4
Description The SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values. This flaw can lead to the system reading the incorrect username, allowing an attacker using a carefully crafted certificate to impersonate another user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-22747
GHSA-2JRG-RF5X-568G

Affected Products

Spring Security