Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-40976: Spring Boot can be tricked into running malicious code

CVE-2026-40976 · published 4 days ago
Summary

Several Spring Boot packages that you may use in Maven have a weakness that could let an attacker cause the application to execute unwanted code. This can lead to data theft or system compromise. Update the affected Spring Boot libraries to the latest released versions as soon as possible.

What to do
  • Update springframework org.springframework.boot:spring-boot to version 4.0.6.
  • Update root io.root.org.springframework.boot:spring-boot to version 4.0.5-root.io.2.
  • Update springframework org.springframework.boot:spring-boot to version 4.0.5-aikido.2.
  • Update root io.root.org.springframework.boot:spring-boot to version 4.0.6-root.io.1.
  • Update springframework org.springframework.boot:spring-boot to version 4.0.6-aikido.1.
  • Update org.springframework.boot:spring-boot to version 4.0.6-aikido.1.
  • Update io.root.org.springframework.boot:spring-boot to version 4.0.6-root.io.1.
Affected software
Ecosystem VendorProductAffected versions
maven springframework org.springframework.boot:spring-boot >= 4.0.0, < 4.0.6
Fix: upgrade to 4.0.6
Root:Maven root io.root.org.springframework.boot:spring-boot < 4.0.5-root.io.2
< 4.0.6-root.io.1
Fix: upgrade to 4.0.5-root.io.2
Root:Maven springframework org.springframework.boot:spring-boot < 4.0.5-aikido.2
< 4.0.6-aikido.1
Fix: upgrade to 4.0.5-aikido.2
Root:Maven – org.springframework.boot:spring-boot < 4.0.6-aikido.1
Fix: upgrade to 4.0.6-aikido.1
Root:Maven – io.root.org.springframework.boot:spring-boot < 4.0.6-root.io.1
Fix: upgrade to 4.0.6-root.io.1
Original advisory text
CVE-2026-40976 in org.springframework.boot:spring-boot - Patched by Root
Root has patched CVE-2026-40976 in the org.springframework.boot:spring-boot package for Root:Maven. Multiple fixed versions available.
Severity
9.1 Critical
CVSS 3.1: 9.1 (NVD)
Exploitation
EPSS <1%
Type
CWE-862Missing Authorization
Timeline
Published23 Sep 2026
Updated27 Sep 2026
First seen28 Apr 2026
Track software like this
Free during beta