CRITICAL
VMware by Broadcom
CVE published 2026-08-27
CVE-2026-59354
CVE-2026-59354 is a critical vulnerability in Spring Security's OAuth2 Authorization Server module, affecting versions 7.0.0 through 7.0.4. The vulnerability allows an attacker with a valid Initial Access Token to register a malicious client with crafted metadata, potentially leading to Stored Cross-Site Scripting (XSS), Privilege Escalation, or Server-Side Request Forgery (SSRF). Administrators and users [truncated]