Back

HIGH

ervlet Path Not Correctly Included in Path Matching of XML Authorization Rules

Published Apr 22, 2026

Description

Vulnerability in Spring Spring Security. If an application uses <sec:intercept-url servlet-path="/servlet-path" pattern="/endpoint/**"/> to define the servlet path for computing a path matcher, then the servlet path is not included and the related authorization rules are not exercised. This can lead to an authorization bypass.This issue affects Spring Security: from 7.0.0 through 7.0.4.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (2)

References (8)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner vmware
Published Apr 22, 2026
Updated Jul 15, 2026
Reserved Jan 9, 2026

CISA Vulnrichment

Updated Apr 22, 2026

NVD

Status Modified
Modified Jul 15, 2026

Red Hat

Severity Important
Public date Apr 22, 2026
Bugzilla 2460489

ENISA EUVD

Assigner vmware
Published Apr 22, 2026
Updated Jul 15, 2026