CVE-2026-59270 is a vulnerability in VMware Spring Framework
Published on August 27, 2026
Spring Security embedded UnboundID LDAP server exposes well-known administrative bind DN on all network interfaces
Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces.
Spring Security 7.1.0
Spring Security 7.0.0 - 7.0.6
Spring Security 6.5.0 - 6.5.11
Spring Security 6.4.0 - 6.4.18
Spring Security 5.8.0 - 5.8.27
Spring Security 5.7.0 - 5.7.25
Vulnerability Analysis
CVE-2026-59270 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and a small impact on availability.
Products Associated with CVE-2026-59270
Want to know whenever a new CVE is published for VMware Spring Framework? stack.watch will email you.
Affected Versions
Spring Security:- Version 7.1.0 is affected.
- Version 7.0.0, <= 7.0.6 is affected.
- Version 6.5.0, <= 6.5.11 is affected.
- Version 6.4.0, <= 6.4.18 is affected.
- Version 5.8.0, <= 5.8.27 is affected.
- Version 5.7.0, <= 5.7.25 is affected.