Link following in Spring Boot - CVE-2026-40977
Published: April 27, 2026
Vulnerability details
The vulnerability allows a local privileged user to corrupt one file on the host.
The vulnerability exists due to improper link resolution in ApplicationPidFileWriter when writing the PID file at a predictable default path. A local privileged user can place a symlink at the PID file location to corrupt one file on the host.
Exploitation requires the application to be configured to use ApplicationPidFileWriter and requires write access to the PID file location.
Affected software
Library Support for Spring
IBM Sterling Control Center
IBM InfoSphere Information Server
MongoDB Enterprise Advanced with IBM
How to mitigate CVE-2026-40977
Library Support for Spring - update to 3.4.18
IBM Sterling Control Center - addressed in versions 6.3.1.0.9, 6.4.1.0.3, 6.4.2.0.4
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 3
MongoDB Enterprise Advanced with IBM - update to 1.16.0