Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-40976

Опубликовано: 28 апр. 2026
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and rely on the default web security filter chain; depend on spring-boot-actuator-autoconfigure; not depend on spring-boot-health. If any of the above does not apply, the application is not vulnerable.

Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*
Версия от 4.0.0 (включая) до 4.0.6 (исключая)

EPSS

Процентиль: 39%
0.00489
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-862
CWE-305

Связанные уязвимости

CVSS3: 9.1
redhat
4 месяца назад

In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and rely on the default web security filter chain; depend on spring-boot-actuator-autoconfigure; not depend on spring-boot-health. If any of the above does not apply, the application is not vulnerable. Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.

CVSS3: 9.1
github
4 месяца назад

Spring Boot's default security filter chain has no authorization rule with Actuator but without Health

EPSS

Процентиль: 39%
0.00489
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-862
CWE-305