Authentication Bypass in Vaadin Framework Versions by Vaadin
CVE-2026-2742

5.3MEDIUM

Key Information:

Vendor

Vaadin

Vendor
CVE Published:
10 March 2026

What is CVE-2026-2742?

An authentication bypass flaw has been discovered in specific versions of the Vaadin framework, affecting particular path patterns that allow unauthorized access. This vulnerability enables attackers to access the '/VAADIN' endpoint without proper authorization, initiating framework initialization and session creation. Users employing Spring Security should upgrade their Vaadin installations to mitigate this issue. Recommended versions include 14.14.1, 23.6.7, 24.9.8, and 25.0.2 or newer. Notably, earlier Vaadin versions between 10 and 13, as well as 15 to 22, are unsupported and must be updated to ensure ongoing security.

Affected Version(s)

flow 1.0.0 <= 2.13.0

flow 3.0.0 <= 23.6.7

flow 24.0.0 <= 24.9.7

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.