← Vulnerability feed

Vulnerability record · CVE-2026-40995 · published 11 June 2026

CVE-2026-40995: Broadcom spring web services improper authentication vulnerability

Broadcom · Spring Web Services

X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped to UserDetails, without applying Spring Security's standard account lifecycle checks (disabled, locked, expired, or credentials-expired accounts). Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.

5.4 CVSS 3.1 Medium EPSS 0.18% · top 93.1% CWE-287 · Improper authentication
5.4CVSS 3.1 base score
0.18%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
4 Sep 2026Last modified by NVD

Description

X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped to UserDetails, without applying Spring Security's standard account lifecycle checks (disabled, locked, expired, or credentials-expired accounts). Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-40995 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-3773Broadcom spring web services xml external entity (xxe) vulnerabilitySpring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (…EPSS 4.1%8.6CVE-2026-40999Broadcom spring web services server-side request forgery (ssrf) vulnerabilityWhen WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebService…EPSS 0.43%8.2CVE-2026-40994Broadcom spring web services insecure default initialization vulnerabilityWss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement …EPSS 0.34%8.2CVE-2026-40998Broadcom spring web services xml external entity (xxe) vulnerabilityJaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the …EPSS 0.39%5.3CVE-2026-40997Broadcom spring web services error message information leak vulnerabilitySeveral Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semantics) to remo…EPSS 0.46%4.8CVE-2026-40996Broadcom spring web services broken cryptographic algorithm vulnerabilityWss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for validation RequestData. Inbou…EPSS 0.15%3.7CVE-2026-41000Broadcom spring web services authentication bypass by capture-replay vulnerabilityWss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, prote…EPSS 0.26%7.5CVE-2026-42018JFrog Artifactory improper authentication leaks anonymous tokenJFrog Artifactory can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled. Because the token …KEVEPSS 9.8%analysed

Source: NIST National Vulnerability Database (record CVE-2026-40995), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.