CVE-2026-40992
CVE-2026-40992 is a medium-severity vulnerability in Vmware Spring Boot with a CVSS 3.x base score of 5.0. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-295.
Key facts
- Severity: Medium (CVSS 3.x base score 5.0)
- EPSS exploit prediction: 0% (7th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-36203
- Weakness: CWE-295
- Affected product: Vmware Spring Boot
- Published:
- Last modified:
Description
Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail property, such as spring.mail.properties.mail.smtp.ssl.checkserveridentity=true, are not affected. Affected versions: Spring Boot 4.0.0 through 4.0.6; 3.5.0 through 3.5.14; 3.4.0 through 3.4.16.
Frequently asked questions
- What is CVE-2026-40992?
- Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail property, such as spring.mail.properties.mail.smtp.ssl.checkserveridentity=true, are not affected. Affected versions: Spring Boot 4.0.0 through 4.0.6; 3.5.0 through 3.5.14; 3.4.0 through 3.4.16.
- How severe is CVE-2026-40992?
- CVE-2026-40992 has a CVSS 3.x base score of 5.0, rated medium severity. It is exploitable over an adjacent network with high attack complexity, requires no privileges and no user interaction. Impact on confidentiality is low, integrity low, and availability low.
- Is CVE-2026-40992 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (7th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-40992?
- CVE-2026-40992 affects Vmware Spring Boot. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-40992?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-40992 have an EU (EUVD) identifier?
- Yes. CVE-2026-40992 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-36203.
- When was CVE-2026-40992 published?
- CVE-2026-40992 was published on 2026-06-11 and last updated on 2026-09-04.
References
Affected products (1)
- cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*
More vulnerabilities in Vmware Spring Boot
- CVE-2023-20873 — Critical (CVSS 9.8): In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed…
- CVE-2021-26987 — Critical (CVSS 9.8): Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are…
- CVE-2017-8046 — Critical (CVSS 9.8): Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions…
- CVE-2026-40976 — Critical (CVSS 9.1): In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all…
- CVE-2026-22733 — High (CVSS 8.2): Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an…
- CVE-2026-22731 — High (CVSS 8.2): Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an…
All CVEs affecting Vmware Spring Boot →
Other CWE-295 (Improper Certificate Validation) vulnerabilities
- CVE-2026-58162 — Critical (CVSS 10.0): The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This…
- CVE-2026-4370 — Critical (CVSS 10.0): A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the…
- CVE-2026-30836 — Critical (CVSS 10.0): Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6…
- CVE-2025-68121 — Critical (CVSS 10.0): During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between…
- CVE-2022-20703 — Critical (CVSS 10.0): Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker…
- CVE-2026-78234 — Critical (CVSS 9.9): A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the…
Browse all CWE-295 (Improper Certificate Validation) vulnerabilities →