CVE-2026-22746

low
Published 2026-04-22 · Modified 2026-04-29
CVSS v3
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v2
VIR risk
2.5

Description

Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.springframework.security:spring-security-core>=5.7.0,<=5.7.22
java Mavenorg.springframework.security:spring-security-core>=5.8.0,<=5.8.24
java Mavenorg.springframework.security:spring-security-core>=6.3.0,<=6.3.15
java Mavenorg.springframework.security:spring-security-core>=6.4.0,<=6.4.15
java Mavenorg.springframework.security:spring-security-core>=6.5.0,<6.5.106.5.10
java Mavenorg.springframework.security:spring-security-core>=7.0.0,<7.0.57.0.5
java MAVENorg.springframework.security:spring-security-core>= 7.0.0, <= 7.0.47.0.5
java MAVENorg.springframework.security:spring-security-core>= 6.5.0, <= 6.5.96.5.10
java MAVENorg.springframework.security:spring-security-core>= 6.4.0, <= 6.4.15
java MAVENorg.springframework.security:spring-security-core>= 6.3.0, <= 6.3.15
java MAVENorg.springframework.security:spring-security-core>= 5.8.0, <= 5.8.24
java MAVENorg.springframework.security:spring-security-core>= 5.7.0, <= 5.7.22

References

Verify integrity in audit chain (admin only). AS-IS.