Authentication Flaw in Spring Web Services by Pivotal Software
CVE-2026-40995
5.4MEDIUM
What is CVE-2026-40995?
An authentication vulnerability exists in Spring Web Services which potentially allows an attacker to obtain a fully authenticated X509AuthenticationToken without undergoing standard account lifecycle checks. This occurs when a certificate is presented and mapped to UserDetails, bypassing essential security mechanisms. As a result, accounts deemed as disabled, locked, expired, or with expired credentials may not be properly respected, leading to unauthorized access scenarios.
Affected Version(s)
Spring Web Services 5.0.0 < 5.0.1.1
Spring Web Services 4.1.0 < 4.1.3.1
Spring Web Services 4.0.0 < 4.0.19
