CVE-2026-22746
published 2026-04-22CVE-2026-22746: Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or #isAccountNonLocked user attributes, to…
PriorityP415low3.7CVSS 3.1
AVNACHPRNUINSUCLINAN
EPSS
0.21%
12.0th percentile
Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or #isAccountNonLocked user attributes, to enable, expire, or lock users, then DaoAuthenticationProvider's timing attack defense can be bypassed for users who are disabled, expired, or locked.This issue affects Spring Security: from 5.7.0 through 5.7.22, from 5.8.0 through 5.8.24, from 6.3.0 through 6.3.15, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| devspaces | openvsx-rhel9 | — | — |
| devspaces | pluginregistry-rhel9 | — | — |
| jenkins | jenkins | — | — |
| ocp-tools-4 | jenkins-rhel8 | — | — |
| ocp-tools-4 | jenkins-rhel9 | — | — |
| spring | spring_security | 5.7.0 – 5.7.22 | — |
| spring | spring_security | 5.8.0 – 5.8.24 | — |
| spring | spring_security | 6.3.0 – 6.3.15 | — |
| spring | spring_security | 6.5.0 – 6.5.9 | — |
| spring | spring_security | 7.0.0 – 7.0.4 | — |
| vmware | spring_security | < 5.7.23 | 5.7.23 |
| vmware | spring_security | >= 5.8.0 < 5.8.25 | 5.8.25 |
| vmware | spring_security | >= 6.3.0 < 6.3.16 | 6.3.16 |
| vmware | spring_security | >= 6.4.0 < 6.4.16 | 6.4.16 |
| vmware | spring_security | >= 6.5.0 < 6.5.10 | 6.5.10 |
| vmware | spring_security | >= 7.0.0 < 7.0.5 | 7.0.5 |
CVSS provenance
nvdv3.13.7LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider
ghsa·2026-04-22
CVE-2026-22746 [LOW] CWE-208 Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider
Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider
Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or #isAccountNonLocked user attributes, to enable, expire, or lock users, then DaoAuthenticationProvider's timing attack defense can be bypassed for users who are disabled, expired, or locked. This issue affects Spring Security: from 5.7.0 through 5.7.22, from 5.8.0 through 5.8.24, from 6.3.0 through 6.3.15, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.
GHSA
GHSA-vxf7-qj7q-83fh: Vulnerability in Spring Spring Security
ghsa_unreviewed·2026-04-22
CVE-2026-22746 [LOW] CWE-208 GHSA-vxf7-qj7q-83fh: Vulnerability in Spring Spring Security
Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or #isAccountNonLocked user attributes, to enable, expire, or lock users, then DaoAuthenticationProvider's timing attack defense can be bypassed for users who are disabled, expired, or locked.This issue affects Spring Security: from 5.7.0 through 5.7.22, from 5.8.0 through 5.8.24, from 6.3.0 through 6.3.15, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.
Red Hat
Spring Security: Spring Security: Timing attack defense bypass allows information disclosure
vendor_redhat·2026-04-22·CVSS 3.7
CVE-2026-22746 [LOW] CWE-208 Spring Security: Spring Security: Timing attack defense bypass allows information disclosure
Spring Security: Spring Security: Timing attack defense bypass allows information disclosure
A flaw was found in Spring Security. If an application uses the UserDetails#isEnabled, #isAccountNonExpired, or #isAccountNonLocked user attributes, an attacker can bypass the DaoAuthenticationProvider's timing attack defense. This bypass allows an attacker to potentially gain limited information about disabled, expired, or locked user accounts, which could aid in further reconnaissance or attacks.
Package: jenkins (OpenShift Developer Tools and Services) - Fix deferred
Package: ocp-tools-4/jenkins-rhel8 (OpenShift Developer Tools and Services) - Fix deferred
Package: ocp-tools-4/jenkins-rhel9 (OpenShift Developer Tools and Services) - Fix deferred
Package: spring-security-core (Red Hat build
No detection rules found.
No public exploits indexed.
2026-04-22
Published