CVE-2026-40997

Source
https://cve.org/CVERecord?id=CVE-2026-40997
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40997.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-40997
Aliases
Downstream
Published
2026-06-11T05:04:08Z
Modified
2026-09-06T11:45:35Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
SOAP security faults leak Spring Security account state
Details

Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semantics) to remote SOAP clients through exception messages or callback outcomes, instead of failing with generic authentication errors. That behavior assists remote attackers in distinguishing valid accounts from invalid ones and inferring lifecycle state.

Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.

Database specific
{
    "cna_assigner": "vmware",
    "cwe_ids": [
        "CWE-209"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40997.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "5.0.0"
                },
                {
                    "fixed": "5.0.1.1"
                },
                {
                    "introduced": "4.1.0"
                },
                {
                    "fixed": "4.1.3.1"
                },
                {
                    "introduced": "4.0.0"
                },
                {
                    "fixed": "4.0.19"
                },
                {
                    "introduced": "3.1.0"
                },
                {
                    "fixed": "3.1.9"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "introduced": "5.0.0"
                },
                {
                    "fixed": "5.0.1"
                },
                {
                    "introduced": "4.1.0"
                },
                {
                    "fixed": "4.1.3"
                },
                {
                    "introduced": "4.0.0"
                },
                {
                    "fixed": "4.0.18"
                },
                {
                    "introduced": "3.1.0"
                },
                {
                    "fixed": "3.1.8"
                }
            ],
            "source": "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / github.com/spring-projects/spring-ws

Affected ranges

Type
GIT
Repo
https://github.com/spring-projects/spring-ws
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "3.1.0"
        },
        {
            "fixed": "3.1.8"
        }
    ],
    "source": "DESCRIPTION"
}

Affected versions

v3.*
v3.1.0
v3.1.1
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40997.json"