User Verification Bypass in Spring Security by Pivotal Software
CVE-2026-47841
7.4HIGH
What is CVE-2026-47841?
A vulnerability exists in applications utilizing Spring Security's WebAuthn feature, potentially allowing user verification bypass when a distributed HTTP session store is employed. This flaw may lead to unauthorized actions being carried out by attackers if they can exploit the HTTP session management process. Affected versions range from Spring Security 6.4.0 up to 7.1.0. Implementations are advised to review their session handling practices to mitigate this risk effectively.
Affected Version(s)
Spring Security 7.1.0
Spring Security 7.0.0 <= 7.0.6
Spring Security 6.5.0 <= 6.5.11
