CVE-2026-47838
Last modified
CVE-2026-47838 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. Affected versions: Spring Security 5.7.0 through 5.7.24; 5.8.0 through 5.8.26; 6.3.0 through 6.3.17; 6.4.0 through 6.4.17; 6.5.0 through 6.5.10.. EPSS estimates a 0.12% chance of exploitation in the next 30 days.
Description
SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. Affected versions: Spring Security 5.7.0 through 5.7.24; 5.8.0 through 5.8.26; 6.3.0 through 6.3.17; 6.4.0 through 6.4.17; 6.5.0 through 6.5.10.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Spring Security | < 5.7.25 |
| Vmware | Spring Security | >= 5.8.0, < 5.8.27 |
| Vmware | Spring Security | >= 6.3.0, < 6.3.18 |
| Vmware | Spring Security | >= 6.4.0, < 6.4.18 |
| Vmware | Spring Security | >= 6.5.0, < 6.5.11 |
References
- https://spring.io/security/cve-2026-47838Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-47838?
How severe is CVE-2026-47838?
How do I fix CVE-2026-47838?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-47831Use of a cryptographically weak random number generator in t…7.7
- CVE-2026-47833setupBpmLogs follows symlink for bpm.log open and chown — co…6.9
- CVE-2026-47834Spring Data JPA's Sort validation can be bypassed when param…6.5
- CVE-2026-47835In Spring AI Vector Stores, special characters could be used…7.5
- CVE-2026-47836The base directory (spring.cloud.config.server.svn.basedir) …8.1
- CVE-2026-47837Missing Authentication for Critical Function vulnerability i…9.8
- CVE-2026-47839A vulnerability allows users authenticating through a federa…9.2
- CVE-2026-4784A vulnerability was found in code-projects Simple Laundry Sy…9.8
- CVE-2026-47840A network attacker positioned between UAA and its LDAP direc…9.3
- CVE-2026-47841An application using Spring Security's WebAuthn support may …7.4
- CVE-2026-47842Applications using AesBytesEncryptor with the two-argument c…6.5
- CVE-2026-47843In specific scenarios involving multiple clients with differ…3.7
Are you affected by CVE-2026-47838?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
