Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-40976: Spring Boot can be tricked into running malicious code
CVE-2026-40976 · published 4 days ago
Summary
Several Spring Boot packages that you may use in Maven have a weakness that could let an attacker cause the application to execute unwanted code. This can lead to data theft or system compromise. Update the affected Spring Boot libraries to the latest released versions as soon as possible.
What to do
- Update springframework org.springframework.boot:spring-boot to version 4.0.6.
- Update root io.root.org.springframework.boot:spring-boot to version 4.0.5-root.io.2.
- Update springframework org.springframework.boot:spring-boot to version 4.0.5-aikido.2.
- Update root io.root.org.springframework.boot:spring-boot to version 4.0.6-root.io.1.
- Update springframework org.springframework.boot:spring-boot to version 4.0.6-aikido.1.
- Update org.springframework.boot:spring-boot to version 4.0.6-aikido.1.
- Update io.root.org.springframework.boot:spring-boot to version 4.0.6-root.io.1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| maven | springframework | org.springframework.boot:spring-boot |
>= 4.0.0, < 4.0.6 Fix: upgrade to 4.0.6
|
| Root:Maven | root | io.root.org.springframework.boot:spring-boot |
< 4.0.5-root.io.2 < 4.0.6-root.io.1 Fix: upgrade to 4.0.5-root.io.2
|
| Root:Maven | springframework | org.springframework.boot:spring-boot |
< 4.0.5-aikido.2 < 4.0.6-aikido.1 Fix: upgrade to 4.0.5-aikido.2
|
| Root:Maven | – | org.springframework.boot:spring-boot |
< 4.0.6-aikido.1 Fix: upgrade to 4.0.6-aikido.1
|
| Root:Maven | – | io.root.org.springframework.boot:spring-boot |
< 4.0.6-root.io.1 Fix: upgrade to 4.0.6-root.io.1
|
Original advisory text
CVE-2026-40976 in org.springframework.boot:spring-boot - Patched by Root
Root has patched CVE-2026-40976 in the org.springframework.boot:spring-boot package for Root:Maven. Multiple fixed versions available.
Severity
9.1
Critical
CVSS 3.1: 9.1 (NVD)
Exploitation
EPSS <1%
Type
CWE-862Missing Authorization
Timeline
Published23 Sep 2026
Updated27 Sep 2026
First seen28 Apr 2026
Track software like this
Free during beta