cbcvebase.
CVE-2026-40982
published 2026-05-07

CVE-2026-40982: Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker…

PriorityP261critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.73%
50.0th percentile
Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected from 5.0.0 through 5.0.2 (inclusive); upgrade to 5.0.3 or greater.

Affected

11 ranges
VendorProductVersion rangeFixed in
log4j_2log4j
springspring_cloud_config>= 3.1.0 < 3.1.143.1.14
springspring_cloud_config>= 4.1.0 < 4.1.104.1.10
springspring_cloud_config>= 4.2.0 < 4.2.74.2.7
springspring_cloud_config>= 4.3.0 < 4.3.34.3.3
springspring_cloud_config>= 5.0.0 < 5.0.35.0.3
vmwarespring_cloud_config>= 3.1.0 < 3.1.143.1.14
vmwarespring_cloud_config>= 4.1.0 < 4.1.104.1.10
vmwarespring_cloud_config>= 4.2.0 < 4.2.74.2.7
vmwarespring_cloud_config>= 4.3.0 < 4.3.34.3.3
vmwarespring_cloud_config>= 5.0.0 < 5.0.35.0.3

Detection & IOCsextracted from sources · hover to see the quote

  • Detect directory traversal attempts targeting the spring-cloud-config-server module by monitoring for specially crafted URLs containing path traversal sequences (e.g., ../) in requests to the config server endpoint.
  • Monitor the spring-cloud-config-server module for requests that result in access to arbitrary text and binary files outside the intended configuration directory, which may indicate successful exploitation.
  • Scope investigation of exploitation to the service account under which the Spring Cloud Config server operates, as successful exploitation is limited to that account's file access permissions.
  • ·Affected versions span multiple release trains: 3.1.0–3.1.13, 4.1.0–4.1.9, 4.2.0–4.2.6, 4.3.0–4.3.2, and 5.0.0–5.0.2. Detection and patching scope should cover all these branches.
  • ·No mitigation is available from Red Hat; patching to a fixed version is the only remediation path.
  • ·The vulnerability is tracked under the spring-cloud-config-server component in Red Hat JBoss Enterprise Application Platform Expansion Pack and also associated with the log4j:2/log4j package in RHEL 8 — verify which component is actually deployed in your environment.

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.