Time-of-check Time-of-use (TOCTOU) Race Condition in Spring Security - CVE-2026-22751
Published: April 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to establish multiple authenticated sessions with a one-time token.
The vulnerability exists due to a time-of-check time-of-use race condition in JdbcOneTimeTokenService when handling concurrent requests to the authentication endpoint. A remote attacker can send concurrent authentication requests using a valid one-time token to establish multiple authenticated sessions with a one-time token.
Only applications that explicitly configure one-time token login with JdbcOneTimeTokenService are vulnerable. The default InMemoryOneTimeTokenService is not affected.
Affected software
Library Support for Spring
IBM Sterling Connect:Direct Web Services
MongoDB Enterprise Advanced with IBM
How to mitigate CVE-2026-22751
Library Support for Spring - update to 3.4.18
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.19, 6.4.0.8
MongoDB Enterprise Advanced with IBM - update to 1.16.0