Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-22747

31
FAUCET Score

CVE-2026-22747 is a vulnerability in Spring Security versions 7.0.0 through 7.0.4 affecting the SubjectX500PrincipalExtractor component, which improperly processes malformed X.509 certificate Common Name (CN) values. This flaw enables attackers to extract incorrect username values from certificates and, with careful certificate crafting, assume the identity of another user. The vulnerability requires network access and valid authentication credentials to exploit, representing a credential-based privilege escalation or impersonation attack. The vulnerability carries a CVSS score of 6.8 (Medium severity) with a network attack vector, high attack complexity, and low privilege requirements. Successful exploitation results in high confidentiality and integrity impacts, as attackers can impersonate legitimate users and access protected resources. The EPSS score of 0.00017 indicates a low probability of exploitation in the wild relative to the CVE landscape. There is no current evidence of active exploitation, and the vulnerability does not appear on the CISA Known Exploited Vulnerabilities list. The low EPSS score and inactive status on vulnerability hotlists suggest limited community attention and no publicly available exploit code. Organizations running affected Spring Security versions should prioritize patching, though the practical exploitation barrier remains relatively high due to the requirement for valid credentials and careful certificate construction.

Impacted Technologies

VendorProductVersion(s)CPE
>= 7.0.0, < 7.0.5CPE matchmatch criteria
cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.8MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
1.6
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.30%
Probability of exploitation in next 30 days
EPSS Percentile
21.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0030 is in the 9th percentile among its peer group of 17,829 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

mavenpatch availablevia ghsa
Product: org.springframework.security:spring-security-webFixed in: 7.0.5

Vendor Advisories (1)

mavenGHSA-2jrg-rf5x-568gmedium

Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates

Apr 22, 2026

References

access.redhat.com / security/cve/CVE-2026-22747
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-22747.json
spring.io / security/cve-2026-22747
Vendor Advisory