CVE-2026-40976 — In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web appl — CVE Database · The Intelligence Room