VDB

CVE-2026-40973

CVE-2026-40973 PUBLISHED CVSS 7 HIGH

A critical security vulnerability, CVE-2026-40976, has been identified in Spring Boot versions 4.0.0 through 4.0.5. This flaw occurs when the default web security configuration fails to enforce authorization, which can allow unauthorized access to all application endpoints in certain servlet-based deployments. In vulnerable applications, exploitation is possible when the app is servlet-based, relies on the default Spring Security filter chain, depends on spring-boot-actuator-autoconfigure, and does not depend on spring-boot-health. Two related Spring Boot flaws have also been disclosed: CVE-2026-40973, which may let a local attacker hijack sessions or potentially execute code by taking control of the ApplicationTemp directory, and CVE-2026-40972, which may let an attacker on the same network use a timing attack against the DevTools remote secret and, in extreme cases, achieve remote code execution.

EPSS 0.01% · 0.9th percentile

Risk Scores

CVSS v3.1
7
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.01%
0.9th percentile

Affected Products

VendorProductVersions
SpringSpring Boot <3.3.19
SpringSpring Boot <2.7.33
SpringSpring Boot <4.0.6
SpringSpring Boot <3.4.16
SpringSpring Boot <3.5.14

Timeline

  • Apr 24, 2026 CVE Published
  • Apr 24, 2026 PoC Published
  • May 7, 2026 Security Advisory
  • May 18, 2026 EPSS Score
  • May 19, 2026 EPSS Score
  • May 20, 2026 EPSS Score
  • May 21, 2026 EPSS Score
  • May 22, 2026 EPSS Score
  • May 23, 2026 EPSS Score
  • May 24, 2026 EPSS Score
  • May 25, 2026 EPSS Score
  • May 26, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›