Spring Boot: Spring Boot: Security bypass due to ineffective default web security
Published Apr 27, 2026
9.1
CRITICALCVSS 3.1
EPSS 0.54%
Description
In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and rely on the default web security filter chain; depend on spring-boot-actuator-autoconfigure; not depend on spring-boot-health. If any of the above does not apply, the application is not vulnerable.
Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.
Affected products
-
- Version 4.0.0StatusaffectedConstraints<4.0.6
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Spring | Spring Boot | unaffected |
|
- ≥ 4.0.0 · < 4.0.6
No data.
Red Hat AMQ Broker 7
spring-boot
Not affected
Red Hat AMQ Broker 7
spring-boot-actuator-autoconfigure
Not affected
Red Hat AMQ Clients
spring-boot
Not affected
Red Hat Data Grid 8
spring-boot
Affected
Red Hat Data Grid 8
spring-boot-actuator-autoconfigure
Not affected
Red Hat Enterprise Linux 8
log4j:2/log4j
Not affected
Red Hat Enterprise Linux 9
log4j
Not affected
Red Hat Fuse 7
spring-boot
Not affected
Red Hat Fuse 7
spring-boot-actuator-autoconfigure
Not affected
Red Hat JBoss Enterprise Application Platform 7
spring-boot
Not affected
Red Hat JBoss Enterprise Application Platform 7
spring-boot-actuator-autoconfigure
Not affected
Red Hat JBoss Enterprise Application Platform 8
spring-boot
Not affected
Red Hat JBoss Enterprise Application Platform 8
spring-boot-actuator-autoconfigure
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
spring-boot
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
spring-boot-actuator-autoconfigure
Not affected
Red Hat OpenShift Dev Spaces
devspaces/openvsx-rhel9
Not affected
Red Hat OpenShift Dev Spaces
devspaces/pluginregistry-rhel9
Not affected
Red Hat Process Automation 7
spring-boot
Not affected
Red Hat Single Sign-On 7
spring-boot
Not affected
Red Hat build of Apache Camel - HawtIO 4
spring-boot
Not affected
Red Hat build of Apache Camel - HawtIO 4
spring-boot-actuator-autoconfigure
Not affected
Red Hat build of Apache Camel for Spring Boot 4
spring-boot
Not affected
Red Hat build of Apache Camel for Spring Boot 4
spring-boot-actuator-autoconfigure
Not affected
Red Hat build of OptaPlanner 8
spring-boot
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat AMQ Broker 7 | spring-boot | Not affected | n/a |
| Red Hat AMQ Broker 7 | spring-boot-actuator-autoconfigure | Not affected | n/a |
| Red Hat AMQ Clients | spring-boot | Not affected | n/a |
| Red Hat Data Grid 8 | spring-boot | Affected | n/a |
| Red Hat Data Grid 8 | spring-boot-actuator-autoconfigure | Not affected | n/a |
| Red Hat Enterprise Linux 8 | log4j:2/log4j | Not affected | n/a |
| Red Hat Enterprise Linux 9 | log4j | Not affected | n/a |
| Red Hat Fuse 7 | spring-boot | Not affected | n/a |
| Red Hat Fuse 7 | spring-boot-actuator-autoconfigure | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | spring-boot | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | spring-boot-actuator-autoconfigure | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | spring-boot | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | spring-boot-actuator-autoconfigure | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | spring-boot | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | spring-boot-actuator-autoconfigure | Not affected | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/openvsx-rhel9 | Not affected | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/pluginregistry-rhel9 | Not affected | n/a |
| Red Hat Process Automation 7 | spring-boot | Not affected | n/a |
| Red Hat Single Sign-On 7 | spring-boot | Not affected | n/a |
| Red Hat build of Apache Camel - HawtIO 4 | spring-boot | Not affected | n/a |
| Red Hat build of Apache Camel - HawtIO 4 | spring-boot-actuator-autoconfigure | Not affected | n/a |
| Red Hat build of Apache Camel for Spring Boot 4 | spring-boot | Not affected | n/a |
| Red Hat build of Apache Camel for Spring Boot 4 | spring-boot-actuator-autoconfigure | Not affected | n/a |
| Red Hat build of OptaPlanner 8 | spring-boot | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This is an Important flaw in Spring Boot that allows security bypass under specific application configurations. When a servlet-based web application lacks custom Spring Security configuration, relies on the default web security filter chain, depends on `spring-boot-actuator-autoconfigure`, and does not include `spring-boot-health`, an attacker can gain unauthorized access to all application endpoints. Red Hat JBoss Data Grid (jdg-8.6) is affected by this vulnerability.
Red Hat mitigation
To mitigate this flaw, ensure that Spring Boot applications either implement their own Spring Security configuration, thereby not relying on the default web security filter chain, or include a dependency on `spring-boot-health`. Applications that do not meet all the specific conditions outlined for vulnerability are not affected. If `spring-boot-actuator-autoconfigure` is not strictly required, consider removing it.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-40976 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2463322 Issue Tracking
- https://github.com/advisories/GHSA-8v8j-3hxp-93wr Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-40976
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40976.json
- https://spring.io/security/cve-2026-40976 Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-40976
Change history (0)
No recorded changes yet.