INCIBE warns on CVE-2026-59270 in Spring Security
INCIBE-CERT and other CSIRTs warned about CVE-2026-59270 in Spring Security, a critical flaw with affected branches already listed.
INCIBE-CERT issued a critical warning about CVE-2026-59270 in Spring Security, a flaw in the embedded UnboundID LDAP server. The vulnerability affects several product branches and, according to the technical notice, can expose administrative credentials to remote exploitation if the LDAP port is reachable.
INCIBE-CERT issued a critical advisory for CVE-2026-59270 in Spring Security, a flaw in the embedded UnboundID LDAP server that affects several product branches. The alert, tracked internally as INCIBE-2026-575, was released on August 21, 2026, along with technical details and fixed versions.
What exactly does CVE-2026-59270 affect?
The vulnerability affects the embedded LDAP server used by Spring Security and is tied to exposure of administrative credentials. According to HeroDevs, the Spring Security team officially disclosed it on August 20, 2026, with a CVSS 3.1 score of 9.4 and vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L.
HunCERT and NKI narrowed the affected branches to 7.1.0, 7.0.0 through 7.0.6, 6.5.0 through 6.5.11, 6.4.0 through 6.4.18, 5.8.0 through 5.8.27, and 5.7.0 through 5.7.25. The same advisory says the default LDAP setup is not secure. Moncloa also reported that the INCIBE-CERT bulletin included branches 5.7, 5.8, 6.4, 6.5, 7.0, and 7.1, along with patched versions 5.7.26, 5.8.28, 6.4.19, 6.5.12, 7.0.7, 7.0.6.1, 7.1.0.1, and 7.1.1.
How is it exploited, and how far does it go?
Exploitation requires the embedded LDAP port to be reachable remotely, with no prior credentials and no user interaction. Mallory and HeroDevs agreed that this fits a remote network attack, and Berigo said the UnboundIdContainer class registers an administrative account and exposes the LDAP listener on all network interfaces.
According to that analysis, an attacker who reaches the port can authenticate with a known administrative DN and modify the in-memory directory. Coverage from 1275.ru added that the flaw can also bypass WebAuthn mechanisms when that embedded LDAP is trusted for authentication, which broadens the impact if a test server ends up exposed in production.
HeroDevs also put the August 2026 patch cycle in context and said 91 CVEs were published in a single day, with CVE-2026-59270 as the only critical issue in the batch. Feedly, meanwhile, classified it as a security configuration vulnerability with hardcoded credentials in Spring Security and confirmed that the only affected product is Spring Security in the listed branches and ranges.
What other regional alerts were issued?
CERT-PY reported critical-severity vulnerabilities in Ubiquiti products on its site, although the available material did not list the specific CVEs. In the region, CTI Pilot also included in its daily roundup a TP-Link advisory dated August 20, 2026, about CVE-2026-19586, a pre-auth command injection issue in Omada gateways configured as an OpenVPN server.
On that case, the technical analysis cited by CTI Pilot said that data sent by the client during the OpenVPN connection setup reaches command execution before authentication is completed. Blogspan added that the flaw affects 18 TP-Link Omada gateway models, with a CVSS 4.0 severity of 9.3, and only when the OpenVPN server is enabled and reachable.
That is in addition to Gitea security advisory AV26-845 from the Canadian Centre for Cyber Security. The agency said that, as of August 14, 2026, Gitea versions earlier than 1.27.1 are affected by vulnerabilities, and added that CISA included CVE-2026-60004 in its KEV catalog on August 25, 2026.
Sources
- CVE-2026-59270 - Exploits & Severityfeedly.com· Feedly
- CVE-2026-59270nki.gov.hu· HunCERT / NKI
- Spring: 91 vulnerabilities patched, one criticalberigo.no· Berigo
- CTI Daily Brief · 2026-08-22ctipilot.ch· CTI Pilot
- El INCIBE-CERT alerta de una vulnerabilidad Spring Security ...moncloa.com· Moncloa
- Обход WebAuthn в Spring Security и выполнение кода в Spring Integration1275.ru· 1275.ru
- Avisos SCIincibe.es· INCIBE
- Administrative Access Exposure in Spring Security Embedded LDAP Server (CVE-2026-59270)mallory.ai· Mallory
- CERT-PY – CERT-PYcert.gov.py· CERT-PY
- CVE-2026-19586 — TP-Link Omada gateways: attacker-supplied data during OpenVPN connection establishment reaches command execution before authentication completes (CVSS 4.0 9.3)ctipilot.ch· CTI Pilot
- Gitea security advisory (AV26-845)cyber.gc.ca· Canadian Centre for Cyber Security
- TP-Link Omada: Kritische VPN-Lücke betrifft 18 Gateway-Modelleblogspan.net· Blogspan
- CVE-2026-59270: Spring Security Embedded LDAP Admin DN Exposureherodevs.com· HeroDevs
- 91 Spring CVEs in a Single Day: Inside the August 2026 Batchherodevs.com· HeroDevs



