SOAP security faults leak Spring Security account state

MEDIUM | JUNE 10, 2026 | CVE-2026-40997

Description

Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semantics) to remote SOAP clients through exception messages or callback outcomes, instead of failing with generic authentication errors. That behavior assists remote attackers in distinguishing valid accounts from invalid ones and inferring lifecycle state, which is a form of user enumeration and information disclosure at the security layer.

Preconditions include use of the affected callback handlers or helpers with username-token, digest, or X.509 validation paths where account status exceptions could propagate to the SOAP layer without uniform BadCredentialsException handling.

Affected Spring Products and Versions

Spring Web Services:

  • 5.0.0 - 5.0.1
  • 4.1.0 - 4.1.3
  • 4.0.0 - 4.0.18
  • 3.1.8 and earlier

Mitigation

Users of affected versions should upgrade to the corresponding fixed version.
Fix versionAvailability
5.0.2OSS
5.0.1.1Enterprise Support Only
4.1.4OSS
4.1.3.1Enterprise Support Only
4.0.19Enterprise Support Only
3.1.9Enterprise Support Only

No further mitigation steps are necessary.

History

  • 2026-06-10: Initial vulnerability report published.

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all