Improper Authentication Affecting com.azure.spring:spring-cloud-azure-autoconfigure package, versions [,7.4.0)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.64% (49th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-COMAZURESPRING-19964537
  • published20 Sept 2026
  • disclosed8 Sept 2026
  • creditUnknown

Introduced: 8 Sep 2026

NewCVE-2026-69854  (opens in a new tab)
CWE-287  (opens in a new tab)

How to fix?

Upgrade com.azure.spring:spring-cloud-azure-autoconfigure to version 7.4.0 or higher.

Overview

Affected versions of this package are vulnerable to Improper Authentication through the AadOidcIdTokenDecoderFactory and AadB2cOidcIdTokenDecoderFactory OIDC ID token decoders in the Spring Cloud Azure OAuth2 login components. An attacker can elevate privileges and sign in as an unauthorized tenant user by supplying a forged or tenant-mismatched ID token that is signed correctly but has an unvalidated iss claim and, in AAD multi-tenant flows, an inconsistent tid claim. This allows unauthorized access to applications that rely on the issuer or tenant claims to restrict which identities may authenticate.

CVSS Base Scores

version 4.0
version 3.1