Skip to content
VMwareCVE-2026-59270

VMware Spring Security: improper authorization

Critical9.4CVE-2026-59270 · Published Aug 27, 2026 · updated Sep 1, 2026

Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18 Spring Security 5.8.0 - 5.8.27 Spring Security 5.7.0 - 5.7.25

VMware advisory

Affected versions

PackageAffectedFixed in
Spring Security
Product
<= 7.1.0No fix yet
>= 7.0.0, <= 7.0.6No fix yet
>= 6.5.0, <= 6.5.11No fix yet
>= 6.4.0, <= 6.4.18No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-863

More VMware advisories

All VMware
Advisory
VMware Spring AMQP: resource leak
Medium6.5Aug 27
VMware Spring Integration: race condition
Medium4.2Aug 27
VMware Spring Integration: improper input validation
Medium6.3Aug 27
VMware Spring Integration: race condition
High8.2Aug 27
VMware Spring Integration: unsafe deserialization
High8.0Aug 27
VMware Spring Integration: link following
Medium6.8Aug 27

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.