CVE-2026-40997

MEDIUM

SOAP security faults leak Spring Security account state

Title source: cna
STIX 2.1

Description

Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semantics) to remote SOAP clients through exception messages or callback outcomes, instead of failing with generic authentication errors. That behavior assists remote attackers in distinguishing valid accounts from invalid ones and inferring lifecycle state. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.

References (1)

Core 1

Scores

CVSS v3 5.3
EPSS 0.0046
EPSS Percentile 36.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-209
Status published
Products (4)
Spring/Spring Web Services 3.1.0 - 3.1.9
Spring/Spring Web Services 4.0.0 - 4.0.19
Spring/Spring Web Services 4.1.0 - 4.1.4
Spring/Spring Web Services 5.0.0 - 5.0.2
Published Jun 11, 2026
Tracked Since Jun 11, 2026