Spring Security Authorization Server Dynamic Client Registration endpoints perform insufficient validation of client metadata
Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.6, CVEs: CVE-2026-59354, Summary: Spring Security Authorization Server Dynamic Client Registration endpoints perform insufficient validation of certain client metadata fields when explicitly enabled. An attacker possessing a valid Initial Access Token can dynamically register a malicious client with crafted metadata. Depending on the metadata provided and the Authorization Server's configuration, this can…
EPSS 0.00 CVSS 9.6 CVE-2026-59354 Spring Security FI