CVE-2026-40982Disclosure(vmware / spring_cloud_config)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch vmware spring_cloud_config systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected from 5.0.0 through 5.0.2 (inclusive); upgrade to 5.0.3 or greater.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • spring_cloud_config

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 3 classified signals
  • Peaked 3d ago at 5 mentions (2026-05-07); latest day: 1
  • 9 total mentions across 4 days

Affected systems

Vendors
Products
spring_cloud_config

Deep dive

Activity timeline9 mentions / 4d
01345Mentions · 2026-05-07: 5Mentions · 2026-05-08: 1Mentions · 2026-05-12: 2Mentions · 2026-05-18: 1Patch / Workaround · 2026-05-07: 2Technical Details · 2026-05-07: 4Technical Details · 2026-05-08: 1Technical Details · 2026-05-12: 105-0705-0805-1205-18
Signal classification3 categories
Disclosure
444.4%
General
333.3%
Patch
222.2%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-05-075
Disclosure2General1Patch2
2026-05-081
Disclosure1
2026-05-122
General2
2026-05-181
Disclosure1
Full discourse9 posts
  • Gray Hats@the_yellow_fall
    Patch

    Spring Cloud Config fixes a 9.1 CVSS directory traversal (CVE-2026-40982) and a GCP secret leak. Secure your distributed system—upgrade to the latest patches! #SpringCloud #CyberSecurity #InfoSec #SpringFramework #DevOps #GCP #CloudSecurity https://securityonline.info/critical-spring-cloud-config-flaws-expose-arbitrary-files-and-gcp-secrets/ https://t.co/cPkBHLAkUl

    Post summary

    The post announces that Spring Cloud Config has patched the CVE‑2026‑40982 directory traversal flaw and a GCP secret leak, urging users to apply the latest updates.

    00011303
    11.7K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-40982 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory

    Post summary

    The post simply notes CVE-2026-40982 with a high CVSS score and critical advisory status, without further technical or exploit details.

    1000025
    210 followersView on X
  • Cyber Edition@CyberEdition
    Patch

    🔥 Critical flaws hit VMware Spring Cloud Config, including CVE-2026-40982 that allows unauthenticated directory traversal and file access on exposed servers. Other bugs expose GCP secrets and sensitive logs. Patch immediately. https://thecyberedition.com/vmware-spring-cloud-config-hit-by-critical-directory-traversal-flaw/ #CyberSecurity #VMware

    Post summary

    A critical directory traversal flaw in VMware Spring Cloud Config (CVE‑2026‑40982) is disclosed, with details of the affected operation, and a prompt to apply a patch immediately.

    0001070
    727 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Spring ❗ CVE-2026-41002 ❗ CVE-2026-40982 ❗ CVE-2026-40981 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-spring-7/ https://t.co/aUKVEzvCWC

    Post summary

    The post announces three new Spring product CVEs and directs readers to additional information via a CERT link, with no PoC, exploit, patch, or detailed technical data provided.

    00000112
    6.7K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-40982-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The post shares a link to an advisory about CVE‑2026‑40982 with related hashtags, but offers no explicit technical, exploit, or mitigation information.

    0000018
    210 followersView on X
  • Mr.Rabbit@01ra66it
    Disclosure

    【CVE-2026-40982: Directory Traversal with spring-cloud-config-server】 Springは、Spring Cloud Config Serverにおけるディレクトリトラバーサル脆弱性 CVE-2026-40982 を公表しました。細工されたURLを送信することで、Spring Cloud Config Serverが本来制限すべき範囲外のファイルアクセスにつながる可能性があります。 Spring Cloud Configは、マイクロサービスや分散システムで設定情報を集中管理するために使われます。そのため、脆弱性の影響は単なるファイル参照にとどまらず、設定、接続情報、Secrets、クラウド権限の露出に波及する可能性があります。 防御側は、利用バージョン、Config Serverの公開範囲、認証設定、`../` を含むリクエスト、Google Secrets Manager等のバックエンド連携を確認すべきです。設定管理基盤は本番環境の中枢に近いため、更新とログ確認をセットで進める必要があります。 #CVE202640982 #SpringCloudConfig #Java #クラウドセキュリティ #SecretsManagement #脆弱性対応 https://spring.io/security/cve-2026-40982

    Post summary

    The post announces the directory traversal vulnerability CVE‑2026‑40982 in Spring Cloud Config Server, outlines potential data exposure, and offers general mitigation advice, but does not provide any PoC, exploit, or evidence of active use.

    00000204
    3.7K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-40982 Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can sen… https://www.cve.org/CVERecord?id=CVE-2026-40982

    Post summary

    A CVE disclosure describing an arbitrary file serving flaw in Spring Cloud Config, with no evidence of PoC, exploitation, or patch details.

    0000098
    57.4K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-40982 📊 Severity: 9.1 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-40982 #CVE-2026-40982 #CVE #Critical #CyberSecurity #InfoSec https://t.co/dtmUX1szRX

    Post summary

    The tweet simply announces the discovery of CVE-2026-40982, listing its severity and referencing the NVD entry, with no technical detail, exploit code, or patch information.

    0000047
    152 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40982 Directory Traversal in Spring Cloud Config Server 3.1.x Through 5.0.x https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40982

    Post summary

    A directory traversal vulnerability (CVE‑2026‑40982) is disclosed for Spring Cloud Config Server versions 3.1.x to 5.0.x.

    0000048
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarespring_cloud_config---

Explore more