← Terug naar overzicht

CVE-2026-59270 affects Spring Security's embedded UnboundID LDAP server (UnboundIdContainer), which unconditionally registers an administrative credential and binds its listener to all available network interfaces. This misconfiguration exposes the LDAP server to unauthorized access from any network interface, potentially allowing attackers to leverage the hardcoded administrative credentials. The vulnerability affects a wide range of Spring Security versions including 5.7.x, 5.8.x, 6.4.x, 6.5.x, 7.0.x, and 7.1.0. Applications using Spring Security's embedded LDAP server for testing or development are particularly at risk. The issue is rooted in the lack of network binding restrictions and the unconditional registration of admin credentials. Organizations using affected versions should apply patches or mitigations as provided by the Spring Security team.

Affected products

  • Spring Security 5.7.0 - 5.7.25
  • Spring Security 5.8.0 - 5.8.27
  • Spring Security 6.4.0 - 6.4.18
  • Spring Security 6.5.0 - 6.5.11
  • Spring Security 7.0.0 - 7.0.6
  • Spring Security 7.1.0
  • UnboundIdContainer (UnboundID LDAP SDK)

Related CVE's

  • CVE-2026-59270

Categories

  • Enterprise Applications
  • Identity & Access
  • Web Technologies