Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-40976

Spring Boot: default web security can be ineffective, allowing unauthorized access to all endpoints

Technology

Spring Boot

CVSS Score

9.1 / 10.0

Affected Versions

4.0.0 to 4.0.5

Upstream Fix

4.0.6

Published

April 28, 2026

OSSeva Coverage

Fixed upstream

Description

In certain circumstances Spring Boot's default web security is ineffective and every endpoint is reachable without authentication. An application is affected only if it is a servlet-based web application, has no Spring Security configuration of its own and relies on the default security filter chain, depends on spring-boot-actuator-autoconfigure, and does not depend on spring-boot-health. Fixed in 4.0.6.

Upstream record: NVD · CVE.org

Is your Spring Boot deployment affected?

If you're running 4.0.0 to 4.0.5, you need this patch. Book a discovery call to get covered.