CVE-2026-40973
published 2026-04-28CVE-2026-40973: A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When…
PriorityP335high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.14%
3.4th percentile
A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.session.persistent` is set to `true` and the attack persists across application restarts, this may allow the attacker to read session information and hijack authenticated users or deploy a gadget chain and execute code as the application's user.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); predictable temp directory / `ApplicationTemp` ownership verification. Versions that are no longer supported are also affected per vendor advisory.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| devspaces | openvsx-rhel9 | — | — |
| devspaces | pluginregistry-rhel9 | — | — |
| spring | spring_boot | >= 2.7.0 < 2.7.33 | 2.7.33 |
| spring | spring_boot | >= 3.3.0 < 3.3.19 | 3.3.19 |
| spring | spring_boot | >= 3.4.0 < 3.4.16 | 3.4.16 |
| spring | spring_boot | >= 3.5.0 < 3.5.14 | 3.5.14 |
| spring | spring_boot | >= 4.0.0 < 4.0.6 | 4.0.6 |
| vmware | spring_boot | < 2.7.33 | 2.7.33 |
| vmware | spring_boot | >= 3.3.0 < 3.3.19 | 3.3.19 |
| vmware | spring_boot | >= 3.4.0 < 3.4.16 | 3.4.16 |
| vmware | spring_boot | >= 3.5.0 < 3.5.14 | 3.5.14 |
| vmware | spring_boot | >= 4.0.0 < 4.0.6 | 4.0.6 |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Vmware Spring Boot up to 4.0.5 temp file
vuldb·2026-04-28·CVSS 7.0
CVE-2026-40973 [HIGH] Vmware Spring Boot up to 4.0.5 temp file
A vulnerability has been found in Vmware Spring Boot up to 2.7.32/3.3.18/3.4.15/3.5.13/4.0.5 and classified as critical. Affected by this vulnerability is an unknown functionality. This manipulation causes insecure temporary file.
This vulnerability is tracked as CVE-2026-40973. The attack is restricted to local execution. No exploit exists.
The affected component should be upgraded.
GHSA
Spring Boot accepts predictable temp directory without ownership verification
ghsa·2026-04-28
CVE-2026-40973 [HIGH] CWE-377 Spring Boot accepts predictable temp directory without ownership verification
Spring Boot accepts predictable temp directory without ownership verification
A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.session.persistent` is set to `true` and the attack persists across application restarts, this may allow the attacker to read session information and hijack authenticated users or deploy a gadget chain and execute code as the application's user.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); predictable temp directory / `ApplicationTemp` ownership verification. Versions that are no longer supported are also affected per vendor advisory.
Red Hat
Spring Boot: Spring Boot: Arbitrary Code Execution and Session Hijacking via predictable temporary directory
vendor_redhat·2026-04-27·CVSS 7.0
CVE-2026-40973 [HIGH] CWE-341 Spring Boot: Spring Boot: Arbitrary Code Execution and Session Hijacking via predictable temporary directory
Spring Boot: Spring Boot: Arbitrary Code Execution and Session Hijacking via predictable temporary directory
A flaw was found in Spring Boot. A local attacker on the same host as the application may be able to take control of the `ApplicationTemp` directory due to predictable temporary directory handling. When the `server.servlet.session.persistent` setting is enabled and the attack persists across application restarts, this could allow the attacker to read session information, hijack authenticated user sessions, or execute arbitrary code as the application's user.
Mitigation: To mitigate this issue, ensure that the `server.servlet.session.persistent` property is set to `false` in your Spring Boot application's configuration. This prevents session information from being written to the pr
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-40973 log4j: Spring Boot: Arbitrary Code Execution and Session Hijacking via predictable temporary directory [fedora-all]
bugzilla·2026-05-08·CVSS 7.0
CVE-2026-40973 [HIGH] CVE-2026-40973 log4j: Spring Boot: Arbitrary Code Execution and Session Hijacking via predictable temporary directory [fedora-all]
CVE-2026-40973 log4j: Spring Boot: Arbitrary Code Execution and Session Hijacking via predictable temporary directory [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-40973 maven-shade-plugin: Spring Boot: Arbitrary Code Execution and Session Hijacking via predictable temporary directory [fedora-all]
bugzilla·2026-05-08·CVSS 7.0
CVE-2026-40973 [HIGH] CVE-2026-40973 maven-shade-plugin: Spring Boot: Arbitrary Code Execution and Session Hijacking via predictable temporary directory [fedora-all]
CVE-2026-40973 maven-shade-plugin: Spring Boot: Arbitrary Code Execution and Session Hijacking via predictable temporary directory [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-40973 Spring Boot: Spring Boot: Arbitrary Code Execution and Session Hijacking via predictable temporary directory
bugzilla·2026-04-28·CVSS 7.0
CVE-2026-40973 [HIGH] CVE-2026-40973 Spring Boot: Spring Boot: Arbitrary Code Execution and Session Hijacking via predictable temporary directory
CVE-2026-40973 Spring Boot: Spring Boot: Arbitrary Code Execution and Session Hijacking via predictable temporary directory
A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.session.persistent` is set to `true` and the attack persists across application restarts, this may allow the attacker to read session information and hijack authenticated users or deploy a gadget chain and execute code as the application's user.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); predictable temp directory / `ApplicationTemp` ownership verification. Versions that are no longer supported are also affected
2026-04-28
Published