QSearchQSearch

CVE-2026-40997

5.3 MEDIUM

Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semant...

Published: 2026-06-11 · Last updated: 2026-06-11

Severity and scoring

CVSS
5.3 MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE
CWE-209

Description

Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semantics) to remote SOAP clients through exception messages or callback outcomes, instead of failing with generic authentication errors. That behavior assists remote attackers in distinguishing valid accounts from invalid ones and inferring lifecycle state. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.

Source: NVD

References

Related CVEs

Same CWE

  • CVE-2026-47248 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js
  • CVE-2026-41730 Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persistence-layer intern... (5.3 MEDIUM)
  • CVE-2025-52611 HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability (3.1 LOW)
  • CVE-2025-52606 HCL iControl was affected by Weak Input Validation vulnerability (4.3 MEDIUM)
  • CVE-2026-9794 A flaw was found in Keycloak (5.3 MEDIUM)