ervlet Path Not Correctly Included in Path Matching of XML Authorization Rules
Published Apr 22, 2026
7.5
HIGHCVSS 3.1
EPSS 0.27%
Description
Vulnerability in Spring Spring Security. If an application uses <sec:intercept-url servlet-path="/servlet-path" pattern="/endpoint/**"/> to define the servlet path for computing a path matcher, then the servlet path is not included and the related authorization rules are not exercised. This can lead to an authorization bypass.This issue affects Spring Security: from 7.0.0 through 7.0.4.
Affected products
-
Affected
- ≥ 7.0.0, ≤ 7.0.4
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Spring | Spring Security | unaffected | Affected
|
- ≥ 7.0.0 · < 7.0.5
No data.
OpenShift Developer Tools and Services
jenkins
Not affected
OpenShift Developer Tools and Services
ocp-tools-4/jenkins-rhel8
Not affected
OpenShift Developer Tools and Services
ocp-tools-4/jenkins-rhel9
Not affected
Red Hat Data Grid 8
spring-security-core
Not affected
Red Hat Fuse 7
org.apache.servicemix.bundles.spring-security-core
Not affected
Red Hat Fuse 7
spring-security-core
Not affected
Red Hat JBoss Enterprise Application Platform 7
spring-security-core
Not affected
Red Hat JBoss Enterprise Application Platform 8
quarkus-spring-security-core-api
Not affected
Red Hat JBoss Enterprise Application Platform 8
spring-security-core
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
quarkus-spring-security-core-api
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
spring-security-core
Not affected
Red Hat OpenShift Dev Spaces
devspaces/openvsx-rhel9
Not affected
Red Hat OpenShift Dev Spaces
devspaces/pluginregistry-rhel9
Not affected
Red Hat Process Automation 7
spring-security-core
Not affected
Red Hat Single Sign-On 7
spring-security-core
Not affected
Red Hat build of Apache Camel - HawtIO 4
spring-security-core
Not affected
Red Hat build of Apache Camel for Spring Boot 4
spring-security-core
Not affected
Red Hat build of Quarkus
quarkus-spring-security-core-api
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Developer Tools and Services | jenkins | Not affected | n/a |
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel8 | Not affected | n/a |
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel9 | Not affected | n/a |
| Red Hat Data Grid 8 | spring-security-core | Not affected | n/a |
| Red Hat Fuse 7 | org.apache.servicemix.bundles.spring-security-core | Not affected | n/a |
| Red Hat Fuse 7 | spring-security-core | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | spring-security-core | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | quarkus-spring-security-core-api | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | spring-security-core | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | quarkus-spring-security-core-api | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | spring-security-core | Not affected | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/openvsx-rhel9 | Not affected | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/pluginregistry-rhel9 | Not affected | n/a |
| Red Hat Process Automation 7 | spring-security-core | Not affected | n/a |
| Red Hat Single Sign-On 7 | spring-security-core | Not affected | n/a |
| Red Hat build of Apache Camel - HawtIO 4 | spring-security-core | Not affected | n/a |
| Red Hat build of Apache Camel for Spring Boot 4 | spring-security-core | Not affected | n/a |
| Red Hat build of Quarkus | quarkus-spring-security-core-api | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- https://access.redhat.com/security/cve/CVE-2026-22754 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2460489 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24612 Advisory
- https://github.com/advisories/GHSA-4vrc-j85c-598c Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-22754
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22754.json
- https://spring.io/security/cve-2026-22754 MitigationVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-22754
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub