SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-59354

CRITICAL · CVSS 9.6 EPSS 0.46%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The vulnerability affects Spring Security's OAuth2 Authorization Server module versions 7.0.0 to 7.0.4, specifically when Dynamic Client Registration is enabled. Insufficient validation of client metadata allows an attacker with a valid Initial Access Token to register a malicious client, potentially leading to Stored Cross-Site Scripting (XSS), Privilege Escalation, or Server-Side Request Forgery (SSRF). Organizations using these versions of Spring Security should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-59354
Severity
CRITICAL
CVSS
9.6
EPSS
0.46%

Original NVD Description

In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation of certain client metadata fields supplied by the registering client. An attacker who possesses a valid Initial Access Token can register a malicious client with crafted metadata, which, depending on server configuration and how the metadata is later rendered or used, may result in Stored Cross-Site Scripting (XSS), Privilege Escalation, or Server-Side Request Forgery (SSRF).

Related CVEs

Other vulnerabilities affecting the same vendor(s)