Authentication Bypass in Vaadin Framework Versions by Vaadin
CVE-2026-2742
5.3MEDIUM
What is CVE-2026-2742?
An authentication bypass flaw has been discovered in specific versions of the Vaadin framework, affecting particular path patterns that allow unauthorized access. This vulnerability enables attackers to access the '/VAADIN' endpoint without proper authorization, initiating framework initialization and session creation. Users employing Spring Security should upgrade their Vaadin installations to mitigate this issue. Recommended versions include 14.14.1, 23.6.7, 24.9.8, and 25.0.2 or newer. Notably, earlier Vaadin versions between 10 and 13, as well as 15 to 22, are unsupported and must be updated to ensure ongoing security.
Affected Version(s)
flow 1.0.0 <= 2.13.0
flow 3.0.0 <= 23.6.7
flow 24.0.0 <= 24.9.7
