CVE-2026-40981Disclosure(vmware / spring_cloud_config)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from unintended GCP projects. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected from 5.0.0 through 5.0.2 (inclusive); upgrade to 5.0.3 or greater.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-639CWE-1220

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • spring_cloud_config

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 4 mentions (2026-05-07); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
spring_cloud_config

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-05-07: 4Mentions · 2026-05-18: 1Technical Details · 2026-05-07: 305-0705-18
Signal classification2 categories
Disclosure
360.0%
General
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-074
Disclosure2General2
2026-05-181
Disclosure1
Full discourse5 posts
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Spring ❗ CVE-2026-41002 ❗ CVE-2026-40982 ❗ CVE-2026-40981 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-spring-7/ https://t.co/aUKVEzvCWC

    Post summary

    The post announces three new Spring product CVEs and references external URLs for additional information, but does not provide technical details, exploits, patches or evidence of active exploitation.

    00000112
    6.7K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-40981 When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from … https://www.cve.org/CVERecord?id=CVE-2026-40981

    Post summary

    The post informs that CVE-2026-40981 allows a crafted request to exploit Google Secrets Manager via Spring Cloud Config, potentially exposing secrets, but it provides no evidence of active use, PoC, or patch.

    0000095
    57.4K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-40981 📊 Severity: 7.5 🚨 Risk Level: High 🧩 Affects: Google Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-40981 #CVE-2026-40981 #CVE #High #Google #CyberSecurity #InfoSec https://t.co/vCAGI02KZN

    Post summary

    A new CVE, CVE-2026-40981, affecting Google has been announced with a severity score of 7.5, but no further details on exploitation, patches, or technical specifics are provided.

    0000045
    152 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40981 Information Disclosure in Spring Cloud Config Google Secrets Manager Backend https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40981

    Post summary

    The text announces CVE-2026-40981 as an information‑disclosure flaw in Spring Cloud Config's Google Secrets Manager backend, without providing PoC, exploit, or mitigation details.

    0000043
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-40981 When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the c… CVSS 7.5 Full analysis → https://sec.kaitan.id/cves/CVE-2026-40981 #Google #CyberSecurity #InfoSec

    Post summary

    The post announces CVE‑2026‑40981 with a CVSS rating of 7.5 and links to a detailed analysis, but does not mention a PoC, exploit code, active attacks, or a patch.

    0000042
    518 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarespring_cloud_config---

Explore more