CVE-2026-22747
published 2026-04-22CVE-2026-22747: Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead…
PriorityP349high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.30%
21.6th percentile
Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user.
This issue affects Spring Security: from 7.0.0 through 7.0.4.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring | spring_security | 7.0.0 – 7.0.4 | — |
| vmware | spring_security | >= 7.0.0 < 7.0.5 | 7.0.5 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2jrg-rf5x-568g: Vulnerability in Spring Spring Security
ghsa_unreviewed·2026-04-22
CVE-2026-22747 [MEDIUM] CWE-297 GHSA-2jrg-rf5x-568g: Vulnerability in Spring Spring Security
Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user.
This issue affects Spring Security: from 7.0.0 through 7.0.4.
GHSA
Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates
ghsa·2026-04-22
CVE-2026-22747 [MEDIUM] CWE-297 Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates
Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates
Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user.
This issue affects Spring Security: from 7.0.0 through 7.0.4.
Red Hat
Spring Security: Spring Security: User impersonation via malformed X.509 certificate Common Name (CN) values
vendor_redhat·2026-04-22·CVSS 6.8
CVE-2026-22747 [MEDIUM] CWE-295 Spring Security: Spring Security: User impersonation via malformed X.509 certificate Common Name (CN) values
Spring Security: Spring Security: User impersonation via malformed X.509 certificate Common Name (CN) values
A flaw was found in Spring Security. This vulnerability allows a remote attacker to impersonate another user. The SubjectX500PrincipalExtractor component incorrectly handles certain malformed X.509 certificate Common Name (CN) values, which can lead to the system reading an incorrect username. By presenting a carefully crafted certificate, an attacker can exploit this to gain unauthorized access.
Package: jenkins (OpenShift Developer Tools and Services) - Not affected
Package: ocp-tools-4/jenkins-rhel8 (OpenShift Developer Tools and Services) - Not affected
Package: ocp-tools-4/jenkins-rhel9 (OpenShift Developer Tools and Services) - Not affected
Package: spring-security-core (
No detection rules found.
No public exploits indexed.
2026-04-22
Published