Skip to content
CVSS 4.2 · MEDIUM

CVE-2026-40968

When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC worker thread and can be inherited by a subsequent unauthenticated request on the same thread. This may allow the subsequent user to gain escalated permissions. Affected versions: Spring gRPC: 1.0.0 - 1.0.2 (fixed in 1.0.3). Older, unsupported versions are also affected.

View on NVD

Severity

Score: 4.2(MEDIUM)
Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
AV: NETWORK
AC: HIGH
PR: LOW
UI: NONE
S: UNCHANGED
C: LOW
I: LOW
A: NONE
Weakness (CWE): CWE-653

EPSS

Probability of exploitation (next 30 days): 0.0003 (0.0%)
Percentile: 9.9%
EPSS: 2026-05-06

Affects

vmware:spring_grpc

Technical description

When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC worker thread and can be inherited by a subsequent unauthenticated request on the same thread. This may allow the subsequent user to gain escalated permissions. Affected versions: Spring gRPC: 1.0.0 - 1.0.2 (fixed in 1.0.3). Older, unsupported versions are also affected.

Published: 4/28/2026, 3:16:30 PM
Last modified: 4/30/2026, 1:32:58 PM

References

HomeEventsBlogResourcesTeam