CVE-2026-40972Disclosure(vmware / spring_boot)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch vmware spring_boot systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this could result in the attacker determining the secret and uploading changed classes, thereby achieving remote code execution in the remote application. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); DevTools remote secret comparison. Versions that are no longer supported are also affected per vendor advisory.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-208

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • spring_boot

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-28); latest day: 2
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
spring_boot

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-04-27: 1Mentions · 2026-04-28: 3Mentions · 2026-04-29: 2Patch / Workaround · 2026-04-27: 1Patch / Workaround · 2026-04-28: 1Technical Details · 2026-04-27: 1Technical Details · 2026-04-28: 2Technical Details · 2026-04-29: 204-2704-2804-29
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-271
Disclosure1
2026-04-283
Disclosure2Patch1
2026-04-292
Disclosure2
Full discourse6 posts
  • CCB Alert@CCBalert
    Patch

    Warning: Critical Auth Bypass, High Session Hijack, and Timing Attack in Spring Boot. #CVE-2026-40976 CVSS: 9.1, CVE-2026-40973 CVSS: 7.0 & CVE-2026-40972 CVSS: 7.5. Attackers may access all endpoints, hijack sessions, or even reach #RCE! https://ccb.belgium.be/advisories/warning-multiple-vulnerabilities-spring-boot-patch-immediately #Patch #Patch

    Post summary

    The advisory warns of high‑severity Spring Boot weaknesses and urges immediate patching, but includes no proof of exploitation or PoC.

    01001203
    7.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40972 An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumsta… https://www.cve.org/CVERecord?id=CVE-2026-40972

    Post summary

    The post cites CVE-2026-40972, noting an attacker can perform a timing attack to learn a remote secret, but offers no PoC, exploit code, or patch details.

    00010344
    57.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40972 An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumsta… https://www.cve.org/CVERecord?id=CVE-2026-40972 ----- Traducción: CVE-2026-40972 Un … http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-40972, describing a timing-based information disclosure threat on a local network; it provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000032
    73 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Spring ❗ CVE-2026-40976 ❗ CVE-2026-40973 ❗ CVE-2026-40972 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-spring-5/ https://t.co/v6vgm120xz

    Post summary

    The post announces three CVE vulnerabilities in Spring products and provides a link for further information, without disclosing PoC, exploit code, patches, or evidence of active exploitation.

    00000136
    6.7K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-40972 📊 Severity: 7.5 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-40972 #CVE-2026-40972 #CVE #High #CyberSecurity #InfoSec https://t.co/157AWufwL5

    Post summary

    The tweet announces the new CVE‑2026‑40972 with a severity score of 7.5, but offers no technical, exploit, or mitigation details.

    0000063
    142 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: Spring Framework discloses CVE-2026-40972, CVE-2026-40973 and CVE-2026-40976 enabling RCE, session hijack and unauthorized endpoint access, all users urged to upgrade immediately. https://threatcluster.io/cluster/multiple-cves-affecting-spring-framework-released-on-april-2-51232475

    Post summary

    Spring Framework discloses three new CVEs that enable RCE, session hijack, and unauthorized endpoint access, and urges users to upgrade immediately.

    0000070
    160 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarespring_boot---

Explore more