CVE-2026-47841: WebAuthn User Verification Bypass via Session Serialization
Published Aug 26, 2026
·Updated
An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a distributed HTTP session store. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18
Affected Software
4 affected components
Spring Spring Security=7.1.0
Spring Spring Security>=7.0.0<=7.0.6
Spring Spring Security>=6.5.0<=6.5.11
Spring Spring Security>=6.4.0<=6.4.18
Event History
Aug 26, 2026
CVE Published
via MITRE·05:08 PM
Data Sourced
via MITRE·05:08 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverity
Frequently Asked Questions
1
Which Spring Security versions are affected?
The affected versions listed are 7.1.0, 7.0.0 through 7.0.6, 6.5.0 through 6.5.11, and 6.4.0 through 6.4.18. Exposure applies to applications using Spring Security WebAuthn support with a distributed HTTP session store.
2
Does an attacker need an account or user interaction to exploit this?
The supplied severity vector indicates network-based exploitation with no privileges required and no user interaction required. It also rates attack complexity as high.