Skip to content
VMwareCVE-2026-22752

VMware Spring Authorization Server: authentication bypass

Critical9.6CVE-2026-22752 · Published Jul 16, 2026 · updated Sep 4, 2026

Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.5.6, from 1.4.0 through 1.4.9, from 1.3.0 through 1.3.10.

VMware advisory

Affected versions

PackageAffectedFixed in
Spring Authorization Server
Product
>= 7.0.0, <= 7.0.4No fix yet
>= 1.5.0, <= 1.5.6No fix yet
>= 1.4.0, <= 1.4.9No fix yet
>= 1.3.0, <= 1.3.10No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-287

More VMware advisories

All VMware
Advisory
VMware Avi Load Balancer: path traversal
High8.8Jul 18
VMware Avi Load Balancer: privilege escalation
High7.1Jul 18
VMware Avi Load Balancer: remote code execution
High8.7Jul 18
VMware Avi Load Balancer: privilege escalation
High7.8Jul 18
VMware Avi Load Balancer: remote code execution
High8.7Jul 18
VMware Avi Load Balancer: improper authorization
High8.3Jul 18

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.