CVE 3.7 LOW

User Attribute Enumeration when Using DaoAuthenticationProvider_CVE-2026-22746

3.7 / 10
LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Description

Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or #isAccountNonLocked user attributes, to enable, expire, or lock users, then DaoAuthenticationProvider's timing attack defense can be bypassed for users who are disabled, expired, or locked.This issue affects Spring Security: from 5.7.0 through 5.7.22, from 5.8.0 through 5.8.24, from 6.3.0 through 6.3.15, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.

Basic Information

ID CVE-2026-22746
Source vmware
Published Apr 22, 2026 at 05:02

Affected Product

Vendor Spring
Product Spring Security
Version 5.7.0
Affected Versions Spring Spring Security 5.7.0
Spring Spring Security 5.8.0
Spring Spring Security 6.3.0
Spring Spring Security 6.5.0
Spring Spring Security 7.0.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.