PT-2026-35548 · Vmware · Spring Boot

Published

2026-04-27

·

Updated

2026-06-05

·

CVE-2026-40976

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Spring Boot versions 4.0.0 through 4.0.5
Description Default web security in certain configurations is ineffective, allowing unauthorized and unauthenticated access to all endpoints. This occurs when a servlet-based web application relies on the default web security filter chain without its own Spring Security configuration, depends on spring-boot-actuator-autoconfigure, and does not depend on spring-boot-health.
Recommendations Upgrade versions 4.0.0 through 4.0.5 to 4.0.6 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40976
GHSA-8V8J-3HXP-93WR

Affected Products

Spring Boot