Remote Code Execution Vulnerability in Spring Cloud Config by Google
CVE-2026-40981

7.5HIGH

Key Information:

Vendor

Spring

Vendor
CVE Published:
7 May 2026

What is CVE-2026-40981?

A vulnerability has been identified in the Spring Cloud Config server when utilizing Google Secrets Manager as a backend. This issue enables an attacker to manipulate requests to the config server, potentially leading to the exposure of sensitive secrets from unintended Google Cloud Platform projects. To mitigate this risk, users are advised to upgrade to the latest patched versions as specified in the affected products listing.

Affected Version(s)

Spring Cloud Config 3.1.0 < 3.1.14

Spring Cloud Config 4.1.0 < 4.1.10

Spring Cloud Config 4.2.0 < 4.2.7

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.