PatchSiren cyber security CVE debrief
CVE-2026-40976 Spring CVE debrief
CVE-2026-40976 is a critical vulnerability in Spring Boot that allows unauthorized access to all endpoints. The vulnerability exists when an application is a servlet-based web application, has no Spring Security configuration of its own, relies on the default web security filter chain, depends on spring-boot-actuator-autoconfigure, and does not depend on spring-boot-health. Affected versions include Spring Boot 4.0.0-4.0.5; upgrade to 4.0.6 or later as recommended by the vendor advisory. This vulnerability has a CVSS score of 9.1 and is considered critical. The CVE was published on April 28, 2026, and last modified on June 30, 2026.
- Vendor
- Spring
- Product
- Spring Boot
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-28
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-28
- Advisory updated
- 2026-07-24
Who should care
Developers and administrators using Spring Boot versions 4.0.0-4.0.5 should be aware of this vulnerability and take necessary actions to mitigate it. This includes upgrading to Spring Boot 4.0.6 or later and ensuring that the application does not rely on the default web security filter chain. Additionally, users of Red Hat products that incorporate Spring Boot may need to take steps to address this vulnerability.
Technical summary
CVE-2026-40976 is a critical vulnerability in Spring Boot that allows unauthorized access to all endpoints. The vulnerability exists when an application meets certain conditions, including being a servlet-based web application with no Spring Security configuration. Affected versions include Spring Boot 4.0.0-4.0.5. The vulnerability has a CVSS score of 9.1 and is considered critical. The CWE associated with this vulnerability is CWE-862 and CWE-305.
Defensive priority
High
Recommended defensive actions
- Upgrade to Spring Boot 4.0.6 or later
- Review and update Spring Security configuration
- Verify application dependencies and configurations
- Monitor for suspicious activity
- Implement compensating controls as needed
Evidence notes
The CVE-2026-40976 vulnerability was published on April 28, 2026, and last modified on June 30, 2026. The vulnerability has a CVSS score of 9.1 and is considered critical. The CWE associated with this vulnerability is CWE-862 and CWE-305. The vulnerability affects Spring Boot versions 4.0.0-4.0.5.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-40976 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-40976
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-40976 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-40976
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://spring.io/security/cve-2026-40976
[email protected] - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-40976
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40976.json
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.