CVE-2026-47877: Spring Security Authorization Server Default Consent Page is vulnerable to Cross-Site Scripting (XSS)
Published Aug 27, 2026
·Updated
Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6
Affected Software
2 affected components
Spring Security Authorization Server Default Consent Page=7.1.0
Spring Security Authorization Server Default Consent Page>=7.0.0<=7.0.6
Event History
Aug 27, 2026
CVE Published
via MITRE·05:20 AM
Data Sourced
via MITRE·05:20 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 AM
DescriptionSeverity
Frequently Asked Questions
1
Who can exploit this issue?
Exploitation can be performed remotely without prior privileges, but it requires user interaction. An attacker would need to cause a user to view content containing attacker-controlled values on the default consent page.
2
Are applications using the default consent page affected?
Yes. The affected component is Spring Security Authorization Server's default consent page, which renders user-controlled values without HTML entity encoding.
3
Which versions are identified as affected?
Spring Security 7.1.0 and Spring Security 7.0.0 through 7.0.6 are listed as affected.