Information Disclosure Vulnerability in Spring Web Services by Spring
CVE-2026-40997
5.3MEDIUM
What is CVE-2026-40997?
Multiple integration paths in Spring Web Services with Spring Security could expose sensitive account states, such as user locks or disabled statuses, to remote SOAP clients. This occurs through detailed exception messages or callback outcomes, contrary to the expected behavior of returning generic authentication errors. Such a flaw allows remote attackers to differentiate between valid and invalid accounts, raising significant security concerns.
Affected Version(s)
Spring Web Services 5.0.0 < 5.0.1.1
Spring Web Services 4.1.0 < 4.1.3.1
Spring Web Services 4.0.0 < 4.0.19
