PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-40976 Spring CVE debrief

CVE-2026-40976 is a critical vulnerability in Spring Boot that allows unauthorized access to all endpoints. The vulnerability exists when an application is a servlet-based web application, has no Spring Security configuration of its own, relies on the default web security filter chain, depends on spring-boot-actuator-autoconfigure, and does not depend on spring-boot-health. Affected versions include Spring Boot 4.0.0-4.0.5; upgrade to 4.0.6 or later as recommended by the vendor advisory. This vulnerability has a CVSS score of 9.1 and is considered critical. The CVE was published on April 28, 2026, and last modified on June 30, 2026.

Vendor
Spring
Product
Spring Boot
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-28
Original CVE updated
2026-07-24
Advisory published
2026-04-28
Advisory updated
2026-07-24

Who should care

Developers and administrators using Spring Boot versions 4.0.0-4.0.5 should be aware of this vulnerability and take necessary actions to mitigate it. This includes upgrading to Spring Boot 4.0.6 or later and ensuring that the application does not rely on the default web security filter chain. Additionally, users of Red Hat products that incorporate Spring Boot may need to take steps to address this vulnerability.

Technical summary

CVE-2026-40976 is a critical vulnerability in Spring Boot that allows unauthorized access to all endpoints. The vulnerability exists when an application meets certain conditions, including being a servlet-based web application with no Spring Security configuration. Affected versions include Spring Boot 4.0.0-4.0.5. The vulnerability has a CVSS score of 9.1 and is considered critical. The CWE associated with this vulnerability is CWE-862 and CWE-305.

Defensive priority

High

Recommended defensive actions

  • Upgrade to Spring Boot 4.0.6 or later
  • Review and update Spring Security configuration
  • Verify application dependencies and configurations
  • Monitor for suspicious activity
  • Implement compensating controls as needed

Evidence notes

The CVE-2026-40976 vulnerability was published on April 28, 2026, and last modified on June 30, 2026. The vulnerability has a CVSS score of 9.1 and is considered critical. The CWE associated with this vulnerability is CWE-862 and CWE-305. The vulnerability affects Spring Boot versions 4.0.0-4.0.5.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-40976 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-40976

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-40976 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-40976

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://spring.io/security/cve-2026-40976

    [email protected] - Vendor Advisory

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/security/cve/CVE-2026-40976

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40976.json

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.