{"id":"GHSA-8v8j-3hxp-93wr","summary":"Spring Boot's default security filter chain has no authorization rule with Actuator but without Health","details":"In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and rely on the default web security filter chain; depend on spring-boot-actuator-autoconfigure; not depend on spring-boot-health. If any of the above does not apply, the application is not vulnerable.\n\nAffected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.","aliases":["CVE-2026-40976"],"modified":"2026-07-17T21:14:54.480871845Z","published":"2026-04-28T00:31:41Z","database_specific":{"cwe_ids":["CWE-862"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-05-06T18:54:08Z","nvd_published_at":"2026-04-28T00:16:24Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40976"},{"type":"PACKAGE","url":"https://github.com/spring-projects/spring-boot"},{"type":"WEB","url":"https://spring.io/security/cve-2026-40976"}],"affected":[{"package":{"name":"org.springframework.boot:spring-boot","ecosystem":"Maven","purl":"pkg:maven/org.springframework.boot/spring-boot"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"4.0.6"}]}],"versions":["4.0.0","4.0.1","4.0.2","4.0.3","4.0.4","4.0.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-8v8j-3hxp-93wr/GHSA-8v8j-3hxp-93wr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}