Information Disclosure Vulnerability in Spring Web Services by Spring
CVE-2026-40997

5.3MEDIUM

Key Information:

Vendor

Spring

Vendor
CVE Published:
11 June 2026

What is CVE-2026-40997?

Multiple integration paths in Spring Web Services with Spring Security could expose sensitive account states, such as user locks or disabled statuses, to remote SOAP clients. This occurs through detailed exception messages or callback outcomes, contrary to the expected behavior of returning generic authentication errors. Such a flaw allows remote attackers to differentiate between valid and invalid accounts, raising significant security concerns.

Affected Version(s)

Spring Web Services 5.0.0 < 5.0.1.1

Spring Web Services 4.1.0 < 4.1.3.1

Spring Web Services 4.0.0 < 4.0.19

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.