← Vulnerability feed

Vulnerability record · CVE-2026-40994 · published 11 June 2026

CVE-2026-40994: Broadcom spring web services insecure default initialization vulnerability

Broadcom · Spring Web Services

Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData. Services that validate WS-Security on the network could therefore accept messages that violate BSP rules, weakening protocol-level checks. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.

8.2 CVSS 3.1 High EPSS 0.34% · top 75.2% CWE-1188 · Insecure default initialization
8.2CVSS 3.1 base score
0.34%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
4 Sep 2026Last modified by NVD

Description

Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData. Services that validate WS-Security on the network could therefore accept messages that violate BSP rules, weakening protocol-level checks. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://spring.io/security/cve-2026-40994 Vendor AdvisoryMitigation

Track CVE-2026-40994 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-3773Broadcom spring web services xml external entity (xxe) vulnerabilitySpring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (…EPSS 4.1%8.6CVE-2026-40999Broadcom spring web services server-side request forgery (ssrf) vulnerabilityWhen WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebService…EPSS 0.43%8.2CVE-2026-40998Broadcom spring web services xml external entity (xxe) vulnerabilityJaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the …EPSS 0.39%5.4CVE-2026-40995Broadcom spring web services improper authentication vulnerabilityX509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped to UserDetails, without appl…EPSS 0.18%5.3CVE-2026-40997Broadcom spring web services error message information leak vulnerabilitySeveral Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semantics) to remo…EPSS 0.46%4.8CVE-2026-40996Broadcom spring web services broken cryptographic algorithm vulnerabilityWss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for validation RequestData. Inbou…EPSS 0.15%3.7CVE-2026-41000Broadcom spring web services authentication bypass by capture-replay vulnerabilityWss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, prote…EPSS 0.26%5.3CVE-2025-48927TeleMessage Spring Boot Actuator heap dump endpoint exposed by insecure defaultTeleMessage through 2025-05-05 ships with Spring Boot Actuator configured to expose the /heapdump endpoint. Because this is an insecure default initi…KEVEPSS 11%analysed

Source: NIST National Vulnerability Database (record CVE-2026-40994), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.