CVE-2018-1260

CRITICAL LAB

Spring Security OAuth < 2.0.14, 2.3.0-2.3.2 - Remote Code Execution via Authorization Endpoint

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-1260. PoCs published by shoucheng3.

AI-analyzed exploit summary This repository contains documentation and sample code for Spring Security OAuth, including details about CVE-2018-1260. It provides setup instructions, sample applications, and integration tests but does not include an actual exploit PoC.

Description

Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contains a remote code execution vulnerability. A malicious user or attacker can craft an authorization request to the authorization endpoint that can lead to remote code execution when the resource owner is forwarded to the approval endpoint.

Exploits (1)

nomisec WRITEUP
by shoucheng3 · poc
https://github.com/shoucheng3/SpringSource__spring-security-oauth_CVE-2018-1260_2-3-2-RELEASE

This repository contains documentation and sample code for Spring Security OAuth, including details about CVE-2018-1260. It provides setup instructions, sample applications, and integration tests but does not include an actual exploit PoC.

Classification
Writeup 90%
Attack Type
Other
Complexity
Moderate
Reliability
Theoretical
Target: Spring Security OAuth 2.3.2.RELEASE
No auth needed
Prerequisites: Maven · Java 1.6 or better · Redis
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:1809
Vendor Advisory x_refsource_confirm
https://pivotal.io/security/cve-2018-1260
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2939
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/104158

Scores

CVSS v3 9.8
EPSS 0.5033
EPSS Percentile 97.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (2)
org.springframework.security.oauth/spring-security-oauth2 2.3.0 - 2.3.3Maven
pivotal_software/spring_security_oauth < 2.0.14
Published May 11, 2018
Tracked Since Feb 18, 2026