CVE-2026-22747 is a vulnerability in Spring Security versions 7.0.0 through 7.0.4 affecting the SubjectX500PrincipalExtractor component, which improperly processes malformed X.509 certificate Common Name (CN) values. This flaw enables attackers to extract incorrect username values from certificates and, with careful certificate crafting, assume the identity of another user. The vulnerability requires network access and valid authentication credentials to exploit, representing a credential-based privilege escalation or impersonation attack. The vulnerability carries a CVSS score of 6.8 (Medium severity) with a network attack vector, high attack complexity, and low privilege requirements. Successful exploitation results in high confidentiality and integrity impacts, as attackers can impersonate legitimate users and access protected resources. The EPSS score of 0.00017 indicates a low probability of exploitation in the wild relative to the CVE landscape. There is no current evidence of active exploitation, and the vulnerability does not appear on the CISA Known Exploited Vulnerabilities list. The low EPSS score and inactive status on vulnerability hotlists suggest limited community attention and no publicly available exploit code. Organizations running affected Spring Security versions should prioritize patching, though the practical exploitation barrier remains relatively high due to the requirement for valid credentials and careful certificate construction.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.0.0, < 7.0.5CPE matchmatch criteria | cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.