CVE-2026-22754
published 2026-04-22CVE-2026-22754: Vulnerability in Spring Spring Security. If an application uses to define the servlet path for computing a path matcher, then the servlet path is not included…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.27%
18.5th percentile
Vulnerability in Spring Spring Security. If an application uses to define the servlet path for computing a path matcher, then the servlet path is not included and the related authorization rules are not exercised. This can lead to an authorization bypass.This issue affects Spring Security: from 7.0.0 through 7.0.4.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring | spring_security | 7.0.0 – 7.0.4 | — |
| vmware | spring_security | >= 7.0.0 < 7.0.5 | 7.0.5 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Spring Security: Spring Security: Authorization bypass due to incorrect servlet path matching
vendor_redhat·2026-04-22·CVSS 7.5
CVE-2026-22754 [HIGH] CWE-551 Spring Security: Spring Security: Authorization bypass due to incorrect servlet path matching
Spring Security: Spring Security: Authorization bypass due to incorrect servlet path matching
A flaw was found in Spring Security. When an application uses `` to define authorization rules, the servlet path may not be correctly included in the path matcher. This oversight can lead to an authorization bypass, allowing a remote attacker to access protected resources without proper authentication or authorization.
Package: jenkins (OpenShift Developer Tools and Services) - Not affected
Package: ocp-tools-4/jenkins-rhel8 (OpenShift Developer Tools and Services) - Not affected
Package: ocp-tools-4/jenkins-rhel9 (OpenShift Developer Tools and Services) - Not affected
Package: spring-security-core (Red Hat build of Apache Camel for Spring Boot 4) - Not affected
Package: spring-security-core
GHSA
GHSA-4vrc-j85c-598c: Vulnerability in Spring Spring Security
ghsa_unreviewed·2026-04-22
CVE-2026-22754 [HIGH] CWE-284 GHSA-4vrc-j85c-598c: Vulnerability in Spring Spring Security
Vulnerability in Spring Spring Security. If an application uses to define the servlet path for computing a path matcher, then the servlet path is not included and the related authorization rules are not exercised. This can lead to an authorization bypass.This issue affects Spring Security: from 7.0.0 through 7.0.4.
GHSA
Spring Security Doesn't Correctly Include Servlet Path in Path Matching of XML Authorization Rules
ghsa·2026-04-22
CVE-2026-22754 [HIGH] CWE-284 Spring Security Doesn't Correctly Include Servlet Path in Path Matching of XML Authorization Rules
Spring Security Doesn't Correctly Include Servlet Path in Path Matching of XML Authorization Rules
Vulnerability in Spring Spring Security. If an application uses to define the servlet path for computing a path matcher, then the servlet path is not included and the related authorization rules are not exercised. This can lead to an authorization bypass. This issue affects Spring Security: from 7.0.0 through 7.0.4.
No detection rules found.
No public exploits indexed.
2026-04-22
Published