Spring Security Authorization Server Authentication Bypass Vulnerability Allowing Privilege Escalation and XSS

Vulnerability

A vulnerability in Spring Security Authorization Server's Dynamic Client Registration endpoints allows for authentication bypass by primary weakness. This issue arises from insufficient validation of client metadata fields when dynamic registration is enabled. An attacker with a valid Initial Access Token could register a malicious client with crafted metadata, potentially leading to Stored Cross-Site Scripting (XSS), Privilege Escalation, or Server-Side Request Forgery (SSRF). The vulnerability affects Spring Authorization Server versions 7.0.0 through 7.0.4, 1.5.0 through 1.5.6, 1.4.0 through 1.4.9, and 1.3.0 through 1.3.10.

Impact

Exploitation of this vulnerability could result in unauthorized authentication, allowing an attacker to bypass authentication mechanisms and potentially gain elevated privileges within the application. Additionally, depending on the crafted metadata and the Authorization Server's configuration, this vulnerability could lead to Stored Cross-Site Scripting (XSS), Privilege Escalation, or Server-Side Request Forgery (SSRF).

Remediation

Users should upgrade to Spring Authorization Server versions 7.0.5, 1.5.7, 1.4.10 (Enterprise Support Only), or 1.3.11 (Enterprise Support Only).

Added: Jul 16, 2026, 10:22 AM
Updated: Jul 16, 2026, 10:22 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
5.2
remediation
0.0
relevance
9.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.