Skip to content
Security Alerts

CVE-2026-59270: Spring Security Embedded LDAP Binds to All Interfaces

The embedded UnboundID LDAP server in Spring Security registers an administrative credential unconditionally and binds its listener to every available network interface...

Summary

ParameterValue
CVE IDCVE-2026-59270
Alert SourceGitHub Advisory - Critical vulnerability
CVE Year2026
Publication Date2026-08-27
VendorVMware (Spring)
ProductSpring Security (UnboundIdContainer)
CVSS Score9.4 (Critical)
EPSS ScoreNo data
CISA KEVNo
RansomwareNot confirmed

Vulnerability Description

Source: NVD / Spring Security Advisory

The embedded UnboundID LDAP server in Spring Security (the UnboundIdContainer class) has two defects that occur together:

  1. it unconditionally registers an administrative credential — the admin account is created regardless of application configuration,
  2. it binds its listener to every available network interface rather than to loopback.

Combined, this means anyone with network access to the host can connect to the LDAP server as an administrator. An LDAP directory typically holds identities and the application’s permission structure, so administrative access to it translates into control over authentication.

Affected versions

  • Spring Security 7.1.0
  • Spring Security 7.0.0 – 7.0.6
  • Spring Security 6.5.0 – 6.5.11
  • Spring Security 6.4.0 – 6.4.18
  • Spring Security 5.8.0 – 5.8.27
  • Spring Security 5.7.0 – 5.7.25

UnboundIdContainer is a component intended for testing and local runs. The risk materialises where a test configuration reached — deliberately or by mistake — a shared or production environment. That happens more often than the design assumes, particularly with Spring profiles inherited between environments.

Required Actions

  1. Upgrade Spring Security to a version outside the ranges above.
  2. Independently of patching, check whether UnboundIdContainer is activated in any profile that runs outside a developer workstation. Look for references to the embedded LDAP server in non-local profiles.
  3. Check whether the LDAP port (389 by default, or 33389 for embedded instances) is listening on addresses other than 127.0.0.1 on your application servers.

Who Is Affected?

The vulnerability affects Java applications using Spring Security in the listed versions where the embedded UnboundID LDAP server is in use.

Spring is the dominant application framework in the financial and insurance sectors and in the software houses that build for them. Spring Security is the authentication layer in those applications, so the 5.7 and 5.8 branches — still maintained in older systems — matter here despite their age.

Sources


Need help securing your systems? nFlo team offers vulnerability management and web application penetration testing services. Contact us.

Learn More

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist