Improper access control in spring-boot - CVE-2026-40973
Published: April 27, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information, hijack authenticated users, or execute arbitrary code.
The vulnerability exists due to improper access control in ApplicationTemp when using a predictable temporary directory for persistent session storage without ownership verification. A local user can take control of the directory used by ApplicationTemp to disclose sensitive information, hijack authenticated users, or execute arbitrary code.
Exploitation requires server.servlet.session.persistent to be set to true and the attack to persist across application restarts.
Affected software
Db2 Developer Extension
MongoDB Enterprise Advanced with IBM
Library Support for Spring
IBM Sterling Control Center
IBM InfoSphere Information Server
How to mitigate CVE-2026-40973
Db2 Developer Extension - update to 1.1.2
Library Support for Spring - update to 3.4.18
IBM Sterling Control Center - addressed in versions 6.3.1.0.9, 6.4.1.0.3, 6.4.2.0.4
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 3
MongoDB Enterprise Advanced with IBM - update to 1.16.0
External References
Related Security Bulletins
- Multiple vulnerabilities in Spring Boot
- Multiple vulnerabilities in IBM Library Support for Spring
- Multiple vulnerabilities in IBM Control Center
- Multiple vulnerabilities in MongoDB Enterprise Advanced with IBM
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in IBM Db2 Developer Extension