Vulnerability Description
Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. This issue affects Spring Security: from 7.0.0 through 7.0.4.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Spring Security | >= 7.0.0, < 7.0.5 |
Related Weaknesses (CWE)
References
- https://spring.io/security/cve-2026-22747Vendor Advisory
FAQ
What is CVE-2026-22747?
CVE-2026-22747 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the userna...
How severe is CVE-2026-22747?
CVE-2026-22747 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-22747?
Check the references section above for vendor advisories and patch information. Affected products include: Vmware Spring Security.