CVE-2026-40976: Spring Boot Default Security Bypass Exposes Endpoints
A critical vulnerability, CVE-2026-40976, has been identified in Spring Boot, rated 9.1 CVSS (CRITICAL) by the National Vulnerability Database. This flaw allows unauthorized access to all endpoints due to ineffective default web security. The vulnerability impacts servlet-based web applications that rely solely on Spring Boot’s default web security filter chain, depend on spring-boot-actuator-autoconfigure, and do not include spring-boot-health in their dependencies.
Attackers can exploit this bypass to gain unfettered access to application endpoints, potentially leading to data exposure or unauthorized actions. The National Vulnerability Database specifies that applications are only vulnerable if all stated conditions are met. This isn’t a theoretical risk; it’s a direct security configuration failure that can be easily exploited by an adversary who understands the Spring Boot ecosystem.
Affected versions are Spring Boot 4.0.0 through 4.0.5. The immediate fix, as advised by the vendor, is to upgrade to Spring Boot 4.0.6 or later. For applications that cannot upgrade immediately, a robust, custom Spring Security configuration is essential to override the vulnerable default. Relying on default security without understanding its limitations is always a gamble, and this CVE proves it.
What This Means For You
- If your organization uses Spring Boot, immediately check for applications meeting the specific vulnerability criteria outlined by the National Vulnerability Database. Prioritize patching to version 4.0.6 or later. For any applications that cannot be patched, implement a strong, custom Spring Security configuration to ensure all endpoints are properly protected. This isn't a 'maybe later' issue; it's a 'patch or get breached' scenario.
Related ATT&CK Techniques
🛡️ Detection Rules
3 rules · 6 SIEM formats3 detection rules auto-generated for this incident, mapped to MITRE ATT&CK. Sigma YAML is free — export to any SIEM format via the Intel Bot.
CVE-2026-40976: Spring Boot Default Security Bypass - Unauthenticated Access to Actuator Endpoints
title: CVE-2026-40976: Spring Boot Default Security Bypass - Unauthenticated Access to Actuator Endpoints
id: scw-2026-04-28-ai-1
status: experimental
level: critical
description: |
Detects unauthenticated access to Spring Boot Actuator endpoints (e.g., /actuator/health, /actuator/info, /actuator/metrics) which are exposed due to the default security bypass in Spring Boot versions 4.0.0-4.0.5. This rule specifically targets the common pattern of accessing these sensitive endpoints without authentication, indicating a potential exploitation of CVE-2026-40976.
author: SCW Feed Engine (AI-generated)
date: 2026-04-28
references:
- https://shimiscyberworld.com/posts/nvd-CVE-2026-40976/
tags:
- attack.initial_access
- attack.t1190
logsource:
category: webserver
detection:
selection:
cs-uri|startswith:
- '/actuator/'
cs-method:
- 'GET'
- 'POST'
sc-status:
- '200'
condition: selection
falsepositives:
- Legitimate administrative activity
Source: Shimi's Cyber World · License & reuse
Indicators of Compromise
| ID | Type | Indicator |
|---|---|---|
| CVE-2026-40976 | Auth Bypass | Spring Boot 4.0.0-4.0.5 |
| CVE-2026-40976 | Auth Bypass | Servlet-based web application with no Spring Security configuration |
| CVE-2026-40976 | Auth Bypass | Dependency on spring-boot-actuator-autoconfigure |
| CVE-2026-40976 | Auth Bypass | No dependency on spring-boot-health |
Source & Attribution
| Source Platform | NVD |
| Channel | National Vulnerability Database |
| Published | April 28, 2026 at 03:16 UTC |
This content was AI-rewritten and enriched by Shimi's Cyber World based on the original source. All intellectual property rights remain with the original author.
Believe this infringes your rights? Submit a takedown request.