CVE-2026-40976Disclosure(vmware / spring_boot)

MEDIUMCVSS 9.1 · CRITICAL

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch vmware spring_boot systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and rely on the default web security filter chain; depend on spring-boot-actuator-autoconfigure; not depend on spring-boot-health. If any of the above does not apply, the application is not vulnerable. Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.

4.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-862CWE-305

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • spring_boot

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 16 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 11 signals
  • Disclosure: 6 classified signals
  • General: 3 classified signals
  • Peaked 1d ago at 5 mentions (2026-05-25); latest day: 2
  • 16 total mentions across 5 days

Affected systems

Vendors
Products
spring_boot

Deep dive

Activity timeline16 mentions / 5d
01345Mentions · 2026-04-27: 3Mentions · 2026-04-28: 4Mentions · 2026-04-29: 2Mentions · 2026-05-25: 5Mentions · 2026-06-05: 2Active Exploitation · 2026-06-05: 2Patch / Workaround · 2026-04-27: 3Patch / Workaround · 2026-04-28: 2Patch / Workaround · 2026-06-05: 2Technical Details · 2026-04-27: 3Technical Details · 2026-04-28: 2Technical Details · 2026-04-29: 2Technical Details · 2026-05-25: 3Technical Details · 2026-06-05: 104-2704-2804-2905-2506-05
Signal classification4 categories
Disclosure
637.5%
Patch
531.3%
General
318.8%
Active Exploitation
212.5%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-04-273
Patch3
2026-04-284
Disclosure1General1Patch2
2026-04-292
Disclosure2
2026-05-255
Disclosure3General2
2026-06-052
Active Exploitation2
Full discourse16 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Critical - Spring Boot default security misconfiguration exposes endpoints (CVE-2026-40976) Under specific conditions, the default security filter chain may lack authorization rules, allowing unauthenticated access to all endpoints when using Actuator without Health. 👉 Affected: >= 4.0.0, <= 4.0.5 | Upgrade: 4.0.6

    Post summary

    Spring Boot 4.0.0‑4.0.5 are vulnerable to unauthenticated access via Actuator endpoints due to a default security misconfiguration; upgrading to 4.0.6 resolves the issue.

    0004195
    237 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    Sources Apache MINA CVE-2026-42779: The Patch That Wasn't Spring Boot CVE-2026-40976: Active Exploitation Post-Patch CISA 72-Hour Patch Deadline Proposal: Why Speed Became the Enemy M-Trends 2026: The 22-Second Hand-Off Window That Broke Patching

    Post summary

    The text signals pressing patch issues and notes that CVE‑2026‑40976 is actively exploited post‑patch, underscoring urgency in remediation efforts.

    1101159
    246 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical Auth Bypass, High Session Hijack, and Timing Attack in Spring Boot. #CVE-2026-40976 CVSS: 9.1, CVE-2026-40973 CVSS: 7.0 &amp; CVE-2026-40972 CVSS: 7.5. Attackers may access all endpoints, hijack sessions, or even reach #RCE! https://ccb.belgium.be/advisories/warning-multiple-vulnerabilities-spring-boot-patch-immediately #Patch #Patch

    Post summary

    Spring Boot is exposed to three CVEs (CVSS 9.1, 7.5, 7.0) that allow auth bypass, session hijack, and potentially RCE; users are urged to apply the patch detailed in the provided advisory.

    01001203
    7.2K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    3. The "Invisible Patch" Problem Not all patches actually work. In April 2026 alone, we saw: Apache MINA CVE-2026-42779: "Patched" deserialization flaw that still had a bypass Spring Boot CVE-2026-40976: "Fixed" auth flaw that attackers exploited 72 hours after patch…

    Post summary

    The post underscores that two recently patched CVEs – a deserialization flaw in Apache MINA and an authentication flaw in Spring Boot – continued to be exploited within a few days of being fixed.

    1000057
    246 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Spring Boot's Default Security Just Broke: CVE-2026-40976 Puts Millions of Applications at Risk. Application is servlet-based traditional Spring MVC or similar No explicit Spring Security configuration relies on defaults Depends on spring-boot-actuator-autoconfigure but…

    Post summary

    The post announces CVE‑2026‑40976, noting that numerous Spring Boot applications might be at risk due to default security settings, but it offers no proof‑of‑concept, exploit details, patch information, or evidence of active exploitation.

    1000058
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    What Happened The Spring Security team disclosed CVE-2026-40976 on April 28, 2026—a flaw in Spring Boot's default web security filter chain that completely fails to protect endpoints under certain conditions. The vulnerability exists in the default autoconfiguration when…

    Post summary

    Spring Security announced CVE‑2026‑40976, highlighting a flaw that can leave endpoints unprotected due to a default autoconfiguration issue. No PoC, exploit, active exploitation, or patch details were included.

    1000054
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Sources Spring Boot's Default Security Just Broke: CVE-2026-40976 Bypasses Authentication on All Endpoints

    Post summary

    An announcement of the CVE‑2026‑40976 vulnerability in Spring Boot’s default security, highlighting that it allows authentication bypass on all endpoints, but no proof‑of‑concept, exploit, or patch details are provided.

    1000044
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Spring Boot's Default Security Just Broke: CVE-2026-40976 Bypasses Authentication on All Endpoints Application is servlet-based traditional Spring MVC or similar No explicit Spring Security configuration relies on defaults Depends on spring-boot-actuator-autoconfigure but…

    Post summary

    The text announces a publicly disclosed CVE (2026‑40976) that allows authentication bypass on all endpoints in Spring Boot applications employing default security via spring‑boot‑actuator‑autoconfigure.

    1000050
    227 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Spring Boot、重大な脆弱性(CVE-2026-40976)を修正-特定条件で全エンドポイントが未認証アクセス可能に https://rocket-boys.co.jp/security-measures-lab/spring-boot-cve-2026-40976-critical-auth-bypass/ #セキュリティ対策Lab #security #securitynews

    Post summary

    The post announces that Spring Boot CVE‑2026‑40976, which permitted unauthenticated access to all endpoints under specific conditions, has been patched.

    00010130
    381 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/2026-04-28-spring-boot-cve-2026-40976-auth-bypass #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text merely references a URL and includes generic hashtags, offering no substantive technical or operational details about CVE-2026-40976.

    0000027
    227 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40976 In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it mus… https://www.cve.org/CVERecord?id=CVE-2026-40976 ----- Traducción: CVE-2026-40976 En … http://infoflow.cloud`

    Post summary

    The post announces a new Spring Boot vulnerability (CVE-2026-40976) that allows unauthorized access to all endpoints under certain conditions.

    0000033
    73 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40976 In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it mus… https://www.cve.org/CVERecord?id=CVE-2026-40976

    Post summary

    The tweet announces a Spring Boot vulnerability that bypasses default web security, permitting unauthorized endpoint access, but includes no PoC, exploit details, patch information, or evidence of active exploitation.

    00000229
    57.3K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Spring ❗ CVE-2026-40976 ❗ CVE-2026-40973 ❗ CVE-2026-40972 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-spring-5/ https://t.co/v6vgm120xz

    Post summary

    The tweet merely lists three Spring product CVEs, offering no further technical details or actionable information.

    00000136
    6.7K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-40976 📊 Severity: 9.1 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-40976 #CVE-2026-40976 #CVE #Critical #CyberSecurity #InfoSec https://t.co/FoSiQ9p1ZD

    Post summary

    The tweet announces the existence and critical severity of CVE-2026-40976, but offers no technical details, PoC, or mitigation information.

    0000052
    142 followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Spring Framework discloses CVE-2026-40972, CVE-2026-40973 and CVE-2026-40976 enabling RCE, session hijack and unauthorized endpoint access, all users urged to upgrade immediately. https://threatcluster.io/cluster/multiple-cves-affecting-spring-framework-released-on-april-2-51232475

    Post summary

    Spring Framework discloses three CVEs causing serious vulnerabilities and urges users to upgrade immediately.

    0000070
    160 followersView on X
  • トミー@メモ@TommiyTw
    Patch

    #後で読む 用メモです→ Spring Boot重大な脆弱性(CVE-2026-40976)を修正-特定条件で全エンドポイントが未認証 ... https://ift.tt/ioqG7Me

    Post summary

    The post announces that Spring Boot CVE-2026-40976 has been fixed, noting that the vulnerability allowed unauthenticated access to all endpoints under specific conditions.

    0000054
    157 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarespring_boot---

Explore more