Vulnerability Details CVE-2026-22751
Vulnerability in Spring Spring Security. Applications that explicitly configure One-Time Token login with JdbcOneTimeTokenService are vulnerable to a Time-of-check Time-of-use (TOCTOU) race condition. This issue affects Spring Security: from 6.4.0 through 6.4.15, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 12.2%
CVSS Severity
CVSS v3 Score 4.8
Products affected by CVE-2026-22751
-
cpe:2.3:a:vmware:spring_security:6.4.0
-
cpe:2.3:a:vmware:spring_security:6.4.1
-
cpe:2.3:a:vmware:spring_security:6.4.10
-
cpe:2.3:a:vmware:spring_security:6.4.11
-
cpe:2.3:a:vmware:spring_security:6.4.2
-
cpe:2.3:a:vmware:spring_security:6.4.3
-
cpe:2.3:a:vmware:spring_security:6.4.4
-
cpe:2.3:a:vmware:spring_security:6.4.5
-
cpe:2.3:a:vmware:spring_security:6.4.6
-
cpe:2.3:a:vmware:spring_security:6.4.7
-
cpe:2.3:a:vmware:spring_security:6.4.8
-
cpe:2.3:a:vmware:spring_security:6.4.9
-
cpe:2.3:a:vmware:spring_security:6.5.0
-
cpe:2.3:a:vmware:spring_security:6.5.1
-
cpe:2.3:a:vmware:spring_security:6.5.2
-
cpe:2.3:a:vmware:spring_security:6.5.3
-
cpe:2.3:a:vmware:spring_security:6.5.4
-
cpe:2.3:a:vmware:spring_security:6.5.5
-
cpe:2.3:a:vmware:spring_security:6.5.9
-
cpe:2.3:a:vmware:spring_security:7.0.0
-
cpe:2.3:a:vmware:spring_security:7.0.4