SB2026100618 - IBM Control Center update for Spring Security
Published: October 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper Authentication (CVE-ID: CVE-2026-47841)
CWE-ID: CWE-287 - Improper Authentication
CVSSv4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass user verification during WebAuthn authentication.
The vulnerability exists due to improper comparison of UserVerificationRequirement in Spring Security WebAuthn support when handling serialized and deserialized HTTP session data in a distributed session store. A remote attacker can use an obtained user's authenticator device to complete WebAuthn authentication without satisfying the user verification step to bypass user verification during WebAuthn authentication.
Only applications that use WebAuthn authentication, explicitly configure userVerification = REQUIRED, and use a distributed HTTP session store are vulnerable.
Remediation
Install update from vendor's website.