Improper access control in Spring Cloud Config - CVE-2026-40981

 

Improper access control in Spring Cloud Config - CVE-2026-40981

Published: May 7, 2026


Vulnerability identifier: #VU130472
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-40981
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in the Spring Cloud Config server Google Secrets Manager backend when handling crafted client requests. A remote attacker can send a specially crafted request to disclose sensitive information.

The issue can expose secrets from unintended GCP projects that the config server is able to access.


Affected software

Spring Cloud Config

How to mitigate CVE-2026-40981

Install security update from vendor's website.

Spring Cloud Config - addressed in versions 3.1.14, 4.1.10, 4.2.7, 4.3.3, 5.0.3

External References

Related Security Bulletins