Back to Vulnerability Directory
CRITICALFixed upstream
CVE-2026-40976
Spring Boot: default web security can be ineffective, allowing unauthorized access to all endpoints
Technology
Spring Boot
CVSS Score
9.1 / 10.0
Affected Versions
4.0.0 to 4.0.5
Upstream Fix
4.0.6
Published
April 28, 2026
OSSeva Coverage
Fixed upstream
Description
In certain circumstances Spring Boot's default web security is ineffective and every endpoint is reachable without authentication. An application is affected only if it is a servlet-based web application, has no Spring Security configuration of its own and relies on the default security filter chain, depends on spring-boot-actuator-autoconfigure, and does not depend on spring-boot-health. Fixed in 4.0.6.
Is your Spring Boot deployment affected?
If you're running 4.0.0 to 4.0.5, you need this patch. Book a discovery call to get covered.