Link following in Spring Boot - CVE-2026-40977

 

Link following in Spring Boot - CVE-2026-40977

Published: April 27, 2026


Vulnerability identifier: #VU128235
CSH Severity: Low
CVSS v4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-40977
CWE-ID: CWE-59
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local privileged user to corrupt one file on the host.

The vulnerability exists due to improper link resolution in ApplicationPidFileWriter when writing the PID file at a predictable default path. A local privileged user can place a symlink at the PID file location to corrupt one file on the host.

Exploitation requires the application to be configured to use ApplicationPidFileWriter and requires write access to the PID file location.


Affected software

Spring Boot
Library Support for Spring
IBM Sterling Control Center
IBM InfoSphere Information Server
MongoDB Enterprise Advanced with IBM

How to mitigate CVE-2026-40977

Install security update from vendor's website.

Spring Boot - addressed in versions 2.7.33, 3.3.19, 3.4.16, 3.5.14, 4.0.6
Library Support for Spring - update to 3.4.18
IBM Sterling Control Center - addressed in versions 6.3.1.0.9, 6.4.1.0.3, 6.4.2.0.4
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 3
MongoDB Enterprise Advanced with IBM - update to 1.16.0

External References

Related Security Bulletins