CVE-2026-22747
Unauthorized User Impersonation when Using X.509 Client Certificates
Record summary
CVE-2026-22747 has a selected CVSS score of 6.8 (medium).
Description
Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. This issue affects Spring Security: from 7.0.0 through 7.0.4.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 22, 2026 · Source: CVE List
Affected products and versions
Showing 12 of 20| Product | Source | Version range | Status |
|---|---|---|---|
OpenShift Developer Tools and ServicesBrowse Red Hat / OpenShift Developer Tools and ServicesjenkinsDefault status: unaffected | CVE List | Version data not supplied | |
OpenShift Developer Tools and ServicesBrowse Red Hat / OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Default status: unaffected | CVE List | Version data not supplied | |
OpenShift Developer Tools and ServicesBrowse Red Hat / OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel9Default status: unaffected | CVE List | Version data not supplied | |
Default status: unaffected | CVE List | Version data not supplied | |
Default status: unaffected | CVE List | Version data not supplied | |
Default status: unaffected | CVE List | Version data not supplied | |
Red Hat JBoss Enterprise Application Platform 7Browse Red Hat / Red Hat JBoss Enterprise Application Platform 7spring-security-coreDefault status: unaffected | CVE List | Version data not supplied | |
Red Hat JBoss Enterprise Application Platform 8Browse Red Hat / Red Hat JBoss Enterprise Application Platform 8quarkus-spring-security-core-apiDefault status: unaffected | CVE List | Version data not supplied | |
Red Hat JBoss Enterprise Application Platform 8Browse Red Hat / Red Hat JBoss Enterprise Application Platform 8spring-security-coreDefault status: unaffected | CVE List | Version data not supplied | |
Red Hat JBoss Enterprise Application Platform Expansion PackBrowse Red Hat / Red Hat JBoss Enterprise Application Platform Expansion Packquarkus-spring-security-core-apiDefault status: unaffected | CVE List | Version data not supplied | |
Red Hat JBoss Enterprise Application Platform Expansion PackBrowse Red Hat / Red Hat JBoss Enterprise Application Platform Expansion Packspring-security-coreDefault status: unaffected | CVE List | Version data not supplied | |
Default status: unaffected | CVE List | Version data not supplied | |