Improper Authentication in Spring Security - CVE-2026-47838
Published: July 26, 2026
Vulnerability details
The vulnerability allows a remote user to impersonate another user.
The vulnerability exists due to improper authentication in SubjectDnX509PrincipalExtractor when processing malformed X.509 certificate CN values. A remote user can present a carefully crafted certificate to impersonate another user.
The issue can cause the extractor to read the wrong value for the username.
Affected software
Crowd Data Center
Bitbucket Data Center
Jira Service Management Data Center
Jira Software Data Center
How to mitigate CVE-2026-47838
Crowd Data Center - update to 7.2.2
Bitbucket Data Center - addressed in versions 9.4.7, 10.2.5, 10.3.2
Jira Service Management Data Center - addressed in versions 10.3.7, 11.3.8
Jira Software Data Center - addressed in versions 10.3.7, 11.3.8