Link following in spring-boot - CVE-2026-40977
Published: April 27, 2026
Vulnerability details
The vulnerability allows a local privileged user to corrupt one file on the host.
The vulnerability exists due to improper link resolution in ApplicationPidFileWriter when writing the PID file at a predictable default path. A local privileged user can place a symlink at the PID file location to corrupt one file on the host.
Exploitation requires the application to be configured to use ApplicationPidFileWriter and requires write access to the PID file location.
Affected software
Db2 Developer Extension
MongoDB Enterprise Advanced with IBM
Library Support for Spring
IBM Sterling Control Center
IBM InfoSphere Information Server
How to mitigate CVE-2026-40977
Db2 Developer Extension - update to 1.1.2
Library Support for Spring - update to 3.4.18
IBM Sterling Control Center - addressed in versions 6.3.1.0.9, 6.4.1.0.3, 6.4.2.0.4
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 3
MongoDB Enterprise Advanced with IBM - update to 1.16.0
External References
Related Security Bulletins
- Multiple vulnerabilities in Spring Boot
- Multiple vulnerabilities in IBM Library Support for Spring
- Multiple vulnerabilities in IBM Control Center
- Multiple vulnerabilities in MongoDB Enterprise Advanced with IBM
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in IBM Db2 Developer Extension