← Vulnerability feed

Vulnerability record · CVE-2026-41000 · published 11 June 2026

CVE-2026-41000: Broadcom spring web services authentication bypass by capture-replay vulnerability

Broadcom · Spring Web Services

Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of UsernameToken nonces and creation timestamps, Timestamp elements, and certain SAML one-time-use semantics could be ineffective even when operators configured a replay cache on the interceptor. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.

3.7 CVSS 3.1 Low EPSS 0.26% · top 83.7% CWE-294 · Authentication bypass by capture-replay
3.7CVSS 3.1 base score
0.26%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
4 Sep 2026Last modified by NVD

Description

Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of UsernameToken nonces and creation timestamps, Timestamp elements, and certain SAML one-time-use semantics could be ineffective even when operators configured a replay cache on the interceptor. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://spring.io/security/cve-2026-41000 Vendor AdvisoryMitigation

Track CVE-2026-41000 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-3773Broadcom spring web services xml external entity (xxe) vulnerabilitySpring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (…EPSS 4.1%8.6CVE-2026-40999Broadcom spring web services server-side request forgery (ssrf) vulnerabilityWhen WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebService…EPSS 0.43%8.2CVE-2026-40994Broadcom spring web services insecure default initialization vulnerabilityWss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement …EPSS 0.34%8.2CVE-2026-40998Broadcom spring web services xml external entity (xxe) vulnerabilityJaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the …EPSS 0.39%5.4CVE-2026-40995Broadcom spring web services improper authentication vulnerabilityX509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped to UserDetails, without appl…EPSS 0.18%5.3CVE-2026-40997Broadcom spring web services error message information leak vulnerabilitySeveral Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semantics) to remo…EPSS 0.46%4.8CVE-2026-40996Broadcom spring web services broken cryptographic algorithm vulnerabilityWss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for validation RequestData. Inbou…EPSS 0.15%9.8CVE-2023-23397Microsoft Outlook improper input validation privilege escalationCVE-2023-23397 is a critical elevation of privilege flaw in Microsoft Outlook caused by improper input validation and an authentication bypass by cap…KEVEPSS 97%analysed

Source: NIST National Vulnerability Database (record CVE-2026-41000), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.