CVE-2026-40997: CWE-209: Generation of Error Message Containing Sensitive Information in Spring Spring Web Services
Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semantics) to remote SOAP clients through exception messages or callback outcomes, instead of failing with generic authentication errors. That behavior assists remote attackers in distinguishing valid accounts from invalid ones and inferring lifecycle state. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.
AI Analysis
Technical Summary
Several integration paths in Spring Web Services combined with Spring Security can leak detailed account state information to remote SOAP clients through exception messages or callback outcomes. Instead of generic authentication failure messages, these detailed errors reveal whether an account is locked or disabled, aiding attackers in distinguishing valid user accounts and inferring their lifecycle state. This behavior affects Spring Web Services versions 3.1.0 through 3.1.8, 4.0.0 through 4.0.18, 4.1.0 through 4.1.3, and 5.0.0 through 5.0.1. The vulnerability is identified as CWE-209 and has a CVSS 3.1 base score of 5.3 (medium severity). There is no vendor advisory or patch available at this time, and no known exploits in the wild have been reported.
Potential Impact
The vulnerability allows remote attackers to obtain sensitive information about user account states (e.g., locked or disabled) via error messages in SOAP responses. This information leakage can be used to differentiate valid accounts from invalid ones and infer user lifecycle states, potentially aiding in targeted attacks or reconnaissance. There is no direct impact on integrity or availability reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, consider configuring the application to suppress detailed error messages in SOAP responses or customize error handling to avoid revealing sensitive account state information.
CVE-2026-40997: CWE-209: Generation of Error Message Containing Sensitive Information in Spring Spring Web Services
Description
Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semantics) to remote SOAP clients through exception messages or callback outcomes, instead of failing with generic authentication errors. That behavior assists remote attackers in distinguishing valid accounts from invalid ones and inferring lifecycle state. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.
CVSS v3.1
Score 5.3medium
Affected software
pkg:maven/org.springframework.ws/spring-ws-coreRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Several integration paths in Spring Web Services combined with Spring Security can leak detailed account state information to remote SOAP clients through exception messages or callback outcomes. Instead of generic authentication failure messages, these detailed errors reveal whether an account is locked or disabled, aiding attackers in distinguishing valid user accounts and inferring their lifecycle state. This behavior affects Spring Web Services versions 3.1.0 through 3.1.8, 4.0.0 through 4.0.18, 4.1.0 through 4.1.3, and 5.0.0 through 5.0.1. The vulnerability is identified as CWE-209 and has a CVSS 3.1 base score of 5.3 (medium severity). There is no vendor advisory or patch available at this time, and no known exploits in the wild have been reported.
Potential Impact
The vulnerability allows remote attackers to obtain sensitive information about user account states (e.g., locked or disabled) via error messages in SOAP responses. This information leakage can be used to differentiate valid accounts from invalid ones and infer user lifecycle states, potentially aiding in targeted attacks or reconnaissance. There is no direct impact on integrity or availability reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, consider configuring the application to suppress detailed error messages in SOAP responses or customize error handling to avoid revealing sensitive account state information.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- vmware
- Date Reserved
- 2026-04-16T02:19:12.969Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a2a59ba318757064921d3b6
Added to database: 06/11/2026, 06:46:18 UTC
Last enriched: 06/24/2026, 14:30:07 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 86
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.