9.1
CVE-2026-59270
- EPSS 0.29%
- Veröffentlicht 27.08.2026 06:17:21
- Zuletzt bearbeitet 01.09.2026 20:36:33
- Erkennungen
Spring Security embedded UnboundID LDAP server exposes well-known administrative bind DN on all network interfaces
Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18 Spring Security 5.8.0 - 5.8.27 Spring Security 5.7.0 - 5.7.25
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Spring Security Version >= 5.7.0 < 5.7.26
VMware ≫ Spring Security Version >= 5.8.0 < 5.8.28
VMware ≫ Spring Security Version >= 6.4.0 < 6.4.19
VMware ≫ Spring Security Version >= 6.5.0 < 6.5.12
VMware ≫ Spring Security Version >= 7.0.0 < 7.0.6.1
VMware ≫ Spring Security Version >= 7.1.0 < 7.1.0.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.29% | 0.21 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
| VMware | 9.4 | 3.9 | 5.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
https://spring.io/security/cve-2026-59270