Description
An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a distributed HTTP session store.
Spring Security 7.1.0
Spring Security 7.0.0 - 7.0.6
Spring Security 6.5.0 - 6.5.11
Spring Security 6.4.0 - 6.4.18
Published: 2026-08-26
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Apply Patch
AI Analysis

Impact

Spring Security’s WebAuthn support may allow a user verification bypass when a distributed HTTP session store is used. The vulnerability description does not detail how the bypass occurs, but it implies that session data stored in a distributed store could potentially be tampered. Based on this description, it is inferred that an attacker who can modify the session payload might trick the framework into accepting it as verified without performing user verification, thereby gaining unauthorized access to protected resources.

Affected Systems

Spring Security versions 7.1.0, 7.0.0‑7.0.6, 6.5.0‑6.5.11, and 6.4.0‑6.4.18 are affected. Any application that uses Spring Security’s WebAuthn support together with a distributed HTTP session store is vulnerable.

Risk and Exploitability

The CVSS score of 7.4 indicates high severity. The EPSS score is less than 1%, implying a low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalogue. Based on the description, it is inferred that the attack vector involves remote manipulation of distributed session data, which would require an attacker to influence the session store—possible if the store is misconfigured or exposed. This makes the risk high for environments where session data may be tampered with, but the probability of widespread exploitation remains low at this time.

Generated by OpenCVE AI on September 5, 2026 at 00:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Spring Security to a version newer than 7.1.0 that contains the WebAuthn session serialization fix.
  • If an upgrade is not possible, disable the use of a distributed HTTP session store for WebAuthn sessions or enforce integrity checks such as signing or encrypting the session payloads.
  • Implement network controls and monitoring to prevent unauthorized modification of session data, and audit session handling for anomalous or tampered payloads.

Generated by OpenCVE AI on September 5, 2026 at 00:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 04 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-502

Fri, 04 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Vmware
Vmware spring Security
Weaknesses CWE-863
CPEs cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:*
Vendors & Products Vmware
Vmware spring Security

Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Spring
Spring spring Security
Weaknesses CWE-287
CWE-502
Vendors & Products Spring
Spring spring Security

Wed, 26 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a distributed HTTP session store. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18
Title WebAuthn User Verification Bypass via Session Serialization
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Spring Spring Security
Vmware Spring Security
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-08-27T03:58:22.127Z

Reserved: 2026-05-20T10:00:51.004Z

Link: CVE-2026-47841

cve-icon Vulnrichment

Updated: 2026-08-26T18:50:28.883Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-26T18:16:33.303

Modified: 2026-09-04T19:41:48.117

Link: CVE-2026-47841

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-05T00:30:18Z

Weaknesses