CVE-2026-22751 is a Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Spring Security's JdbcOneTimeTokenService component affecting versions 6.4.0-6.4.15, 6.5.0-6.5.9, and 7.0.0-7.0.4. The vulnerability impacts only applications that explicitly configure One-Time Token login functionality. An attacker could exploit this race condition to bypass one-time token authentication mechanisms by manipulating the timing between token validation and use. The vulnerability has a CVSS 3.1 score of 4.8 (MEDIUM) with a network-based attack vector, high attack complexity, and no authentication requirement. The potential impact is limited to low-level confidentiality and integrity breaches, with no availability impact. The high attack complexity requirement makes real-world exploitation more difficult, and the relatively low EPSS score of 0.00025 indicates minimal widespread threat probability. There is no evidence of active exploitation, and the vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog. No public exploit code is currently available, and the vulnerability shows minimal community attention. Organizations using affected Spring Security versions should apply patches, though the risk level does not warrant emergency prioritization given the technical exploitation barriers and lack of active threat activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.4.0, < 6.4.16CPE matchmatch criteria | cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:* | ||
>= 6.5.0, < 6.5.10CPE matchmatch criteria | cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:* | ||
>= 7.0.0, < 7.0.5CPE matchmatch criteria | cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.