Improper Certificate Validation in Spring Boot - CVE-2026-40992

 

Improper Certificate Validation in Spring Boot - CVE-2026-40992

Published: June 11, 2026


Vulnerability identifier: #VU134322
CSH Severity: Medium
CVSS v4: 2.3 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-40992
CWE-ID: CWE-295
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information, modify data, or cause a denial of service.

The vulnerability exists due to improper certificate validation in mail auto-configuration when establishing SSL/TLS connections to a mail server. A remote attacker can present a crafted server certificate to disclose sensitive information, modify data, or cause a denial of service.

Applications that explicitly enable the JavaMail server identity check property are not affected.


Affected software

Spring Boot
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data

How to mitigate CVE-2026-40992

Install security update from vendor's website.

Spring Boot - addressed in versions 3.4.17, 3.5.14.1, 3.5.15, 4.0.6.1, 4.0.7
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.4.0 Patch 3

External References

Related Security Bulletins