CVE-2026-59354 CRITICAL

CVE-2026-59354: Spring Security OAuth2 Authorization Server: Insufficient validation of Dynamic Client Registration metadata

Vendor Vmware By Broadcom
Product Spring Security (OAuth2 Authorization Server module)
Weakness CWE-20 · Input validation
Published August 27, 2026
Last update August 28, 2026

CVSS base score

9.6/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

What the vulnerability does

01Description

In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation of certain client metadata fields supplied by the registering client. An attacker who possesses a valid Initial Access Token can register a malicious client with crafted metadata, which, depending on server configuration and how the metadata is later rendered or used, may result in Stored Cross-Site Scripting (XSS), Privilege Escalation, or Server-Side Request Forgery (SSRF).

Key dates

02Disclosure timeline

August 27, 2026 CVE published
August 28, 2026 Record updated

Related vulnerabilities

04Related CVE