Description
Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces.
Spring Security 7.1.0
Spring Security 7.0.0 - 7.0.6
Spring Security 6.5.0 - 6.5.11
Spring Security 6.4.0 - 6.4.18
Spring Security 5.8.0 - 5.8.27
Spring Security 5.7.0 - 5.7.25
Published: 2026-08-27
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized LDAP Administrative Access
Action: Immediate Patch
AI Analysis

Impact

Spring Security’s embedded UnboundID LDAP server automatically registers a default administrative credential and binds to all network interfaces. This exposure allows attackers to discover the well‑known bind DN and gain administrative access to the LDAP directory. This privileged access can compromise confidentiality, integrity, and availability of directory data and all services that rely on it.

Affected Systems

Affected releases include Spring Security 7.1.0, 7.0.0‑7.0.6, 6.5.0‑6.5.11, 6.4.0‑6.4.18, 5.8.0‑5.8.27, and 5.7.0‑5.7.25. The vulnerability resides in the UnboundID LDAP integration bundled with these versions.

Risk and Exploitability

The CVSS score of 9.4 indicates high severity. The EPSS score of < 1% indicates a low but non‑zero exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the exposed administrative DN over any network interface the server listens on, making local or remote network compromise a realistic threat. Lacking additional authentication controls, an attacker with network reach can perform LDAP administration without further credentials.

Generated by OpenCVE AI on September 2, 2026 at 08:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Spring Security to a patched release that removes the default administrative DN and restricts the embedded LDAP listener to authorized interfaces
  • If the embedded LDAP server is not required for your application, disable or remove the UnboundID integration from the Spring Security configuration
  • Configure firewall or network ACL rules to block all unnecessary inbound traffic to the port used by the embedded LDAP service

Generated by OpenCVE AI on September 2, 2026 at 08:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 02 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-620

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Vmware
Vmware spring Security
Weaknesses CWE-863
CPEs cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:*
Vendors & Products Vmware
Vmware spring Security

Fri, 28 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 27 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
First Time appeared Spring
Spring spring Security
Weaknesses CWE-200
CWE-620
Vendors & Products Spring
Spring spring Security

Thu, 27 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18 Spring Security 5.8.0 - 5.8.27 Spring Security 5.7.0 - 5.7.25
Title Spring Security embedded UnboundID LDAP server exposes well-known administrative bind DN on all network interfaces
References
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

Spring Spring Security
Vmware Spring Security
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-08-28T16:52:28.234Z

Reserved: 2026-07-04T18:13:09.972Z

Link: CVE-2026-59270

cve-icon Vulnrichment

Updated: 2026-08-27T14:16:23.036Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-27T06:17:21.223

Modified: 2026-09-01T20:36:33.887

Link: CVE-2026-59270

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T08:30:13Z

Weaknesses