CVE-2026-40995 is an improper-authentication vulnerability in Spring Web Services spring-ws-security. X509AuthenticationProvider can create a fully authenticated X509AuthenticationToken for a presented X.509 certificate that maps to a UserDetails record without applying Spring Security account lifecycle validation. Consequently, the provider does not reject accounts marked disabled, locked, expired, or credentials-expired. Affected versions are Spring Web Services 3.1.0 through 3.1.8, 4.0.0 through 4.0.18, 4.1.0 through 4.1.3, and 5.0.0 through 5.0.1.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authentication-bypass weakness in Spring Web Services' spring-ws-security component. Its X509AuthenticationProvider can authenticate a certificate-mapped user without enforcing standard Spring Security account-state checks, potentially allowing disabled, locked, expired, or credentials-expired accounts to be treated as fully authenticated.
A disabled account bypass vulnerability in the same Spring security release, where X509AuthenticationProvider ignores disabled, locked, or expired account state.
Another Spring Web Services vulnerability mentioned only in passing; described here as an X509AuthenticationProvider bypass issue.
An authentication bypass vulnerability in Spring Web Services / Spring Security X.509 authentication handling where certificate-based authentication could succeed for accounts that should have been rejected due to disabled, locked, expired, or credentials-expired status.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.