Web Application Vulnerability in Spring Security by Pivotal Software
CVE-2026-47877

8.2HIGH

Key Information:

Vendor

Spring

Vendor
CVE Published:
27 August 2026

What is CVE-2026-47877?

The Spring Security Authorization Server exposes a vulnerability where the default consent page improperly renders user-controlled values without adequate HTML entity encoding. This flaw could lead to potential injection attacks, allowing malicious users to manipulate the displayed content, which may harm the user experience and compromise application integrity. Given the various versions affected, it is crucial for organizations utilizing Spring Security to address this issue promptly.

Affected Version(s)

Spring Security 7.1.0

Spring Security 7.0.0 <= 7.0.6

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.