Improper Authentication in Spring Security - CVE-2026-47838

 

Improper Authentication in Spring Security - CVE-2026-47838

Published: July 26, 2026


Vulnerability identifier: #VU139383
CSH Severity: Low
CVSS v4: 7.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-47838
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to impersonate another user.

The vulnerability exists due to improper authentication in SubjectDnX509PrincipalExtractor when processing malformed X.509 certificate CN values. A remote user can present a carefully crafted certificate to impersonate another user.

The issue can cause the extractor to read the wrong value for the username.


Affected software

Spring Security
Crowd Data Center
Bitbucket Data Center
Jira Service Management Data Center
Jira Software Data Center

How to mitigate CVE-2026-47838

Install security update from vendor's website.

Spring Security - update to 6.5.11
Crowd Data Center - update to 7.2.2
Bitbucket Data Center - addressed in versions 9.4.7, 10.2.5, 10.3.2
Jira Service Management Data Center - addressed in versions 10.3.7, 11.3.8
Jira Software Data Center - addressed in versions 10.3.7, 11.3.8

External References

Related Security Bulletins