CVE-2026-40973Patch(vmware / spring_boot)

LOWCVSS 7.0 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch vmware spring_boot systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.session.persistent` is set to `true` and the attack persists across application restarts, this may allow the attacker to read session information and hijack authenticated users or deploy a gadget chain and execute code as the application's user. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); predictable temp directory / `ApplicationTemp` ownership verification. Versions that are no longer supported are also affected per vendor advisory.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-377

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • spring_boot

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • General: 2 classified signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-28); latest day: 2
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
spring_boot

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-04-27: 1Mentions · 2026-04-28: 3Mentions · 2026-04-29: 2Patch / Workaround · 2026-04-27: 1Patch / Workaround · 2026-04-28: 1Technical Details · 2026-04-27: 1Technical Details · 2026-04-28: 1Technical Details · 2026-04-29: 204-2704-2804-29
Signal classification3 categories
Patch
233.3%
General
233.3%
Disclosure
233.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-271
Patch1
2026-04-283
General2Patch1
2026-04-292
Disclosure2
Full discourse6 posts
  • CCB Alert@CCBalert
    Patch

    Warning: Critical Auth Bypass, High Session Hijack, and Timing Attack in Spring Boot. #CVE-2026-40976 CVSS: 9.1, CVE-2026-40973 CVSS: 7.0 & CVE-2026-40972 CVSS: 7.5. Attackers may access all endpoints, hijack sessions, or even reach #RCE! https://ccb.belgium.be/advisories/warning-multiple-vulnerabilities-spring-boot-patch-immediately #Patch #Patch

    Post summary

    The tweet highlights several high‑severity vulnerabilities in Spring Boot, urging users to apply the available patches immediately.

    01001203
    7.2K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40973 A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.session.persistent` … https://www.cve.org/CVERecord?id=CVE-2026-40973 ----- Traducción: CVE-2026-40973 Un … http://infoflow.cloud`

    Post summary

    The post announces the existence of CVE‑2026‑40973, describing a local privilege escalation risk involving the ApplicationTemp directory, but provides no PoC, exploit code, patch information, or evidence of active exploitation.

    0000027
    73 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40973 A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.session.persistent` … https://www.cve.org/CVERecord?id=CVE-2026-40973

    Post summary

    CVE‑2026‑40973 is a local privilege escalation that allows an attacker on the same host to control the ApplicationTemp directory via server.servlet.session.persistent. No PoC, exploit code, patch, or active exploitation is mentioned.

    00000264
    57.3K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Spring ❗ CVE-2026-40976 ❗ CVE-2026-40973 ❗ CVE-2026-40972 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-spring-5/ https://t.co/v6vgm120xz

    Post summary

    The text merely lists three Spring product CVEs and points to external links for more information, without providing specific details, PoC, or exploitation evidence.

    00000136
    6.7K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-40973 📊 Severity: 7.0 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-40973 #CVE-2026-40973 #CVE #High #CyberSecurity #InfoSec https://t.co/tkm1eFRjBr

    Post summary

    A brief tweet announces CVE-2026-40973 with a severity score, but offers no technical details, exploits, or mitigation information.

    0000053
    142 followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Spring Framework discloses CVE-2026-40972, CVE-2026-40973 and CVE-2026-40976 enabling RCE, session hijack and unauthorized endpoint access, all users urged to upgrade immediately. https://threatcluster.io/cluster/multiple-cves-affecting-spring-framework-released-on-april-2-51232475

    Post summary

    The text announces the disclosure of three CVEs in Spring Framework, highlights severe impact (RCE, session hijack, unauthorized access), and urges users to apply available patches immediately.

    0000070
    160 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarespring_boot---

Explore more