Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-22752 -- CVSS 9.6 Vulnerability Briefing

CVE-2026-22752 | CVSS 9.6 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-22752 is a critical authentication bypass vulnerability affecting Spring Security's Spring Authorization Server, impacting versions 7.0.0 through 7.0.4 and 1.5.0 through an unspecified later release in the 1.x branch.

Technical Detail

The vulnerability is classified as an authentication bypass by primary weakness, meaning an attacker can circumvent the authorization server's primary authentication controls without supplying valid credentials. The exact trigger mechanism has not been fully disclosed publicly, but flaws of this class in OAuth2/OIDC authorization servers typically allow an attacker to obtain tokens, impersonate clients or users, or gain unauthorized access to protected resources. If exploited, the impact includes full authentication bypass against any application or service relying on the affected Spring Authorization Server instance for identity and access control decisions.

Exploitation Status

No known exploit exists for this vulnerability at this time. It is not listed in CISA's Known Exploited Vulnerabilities catalog. Despite the critical CVSS score of 9.6, there is no public proof-of-concept code and no confirmed exploitation activity as of July 23, 2026. This status should be monitored closely given the severity and the widespread use of Spring Security components in enterprise Java environments.

Who Is Targeting This

No specific threat actor attribution at this time. Neither confirmed nor reported threat actor activity has been associated with this CVE as of the date of this briefing.

What To Do

Organizations running Spring Authorization Server should treat this as a high-priority patch given the critical severity rating and the nature of the bypass. Upgrade Spring Authorization Server out of the affected version ranges immediately: apply the latest patched release above 7.0.4 for the 7.x branch, and the corresponding fixed release for the 1.5.x branch as identified in the Spring Security advisory. If immediate patching is not feasible, consider placing the authorization server behind additional network-layer access controls to limit exposure to trusted clients only. Review authorization server logs for anomalous token issuance patterns or unexpected client authentication events as a detection measure. Monitor the Spring Security project's official security advisories and the CISA KEV catalog for updates to exploitation status.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →