THREAT OPS › Threat News › [NVD] CVE-2026-40994 (HIGH 8.2) — Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData. Services that validate WS-Security on the network could therefore accept messages that violate BSP rules, weakening
[NVD] CVE-2026-40994 (HIGH 8.2) — Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData. Services that validate WS-Security on the network could therefore accept messages that violate BSP rules, weakening
CVE-2026-40994 CVSS: 8.2 HIGH Published: 2026-06-11T07:16:27.297
Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData. Services that validate WS-Security on the network could therefore accept messages that violate BSP rules, weakening protocol-level checks.
Affected versions: Spring Web
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-40994cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-40994