Home

Description

When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC worker thread and can be inherited by a subsequent unauthenticated request on the same thread. This may allow the subsequent user to gain escalated permissions. Affected versions: Spring gRPC: 1.0.0 - 1.0.2 (fixed in 1.0.3). Older, unsupported versions are also affected.

PUBLISHED Reserved 2026-04-16 | Published 2026-04-28 | Updated 2026-04-28 | Assigner vmware




MEDIUM: 4.3CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Problem types

CWE-653: Improper Isolation or Compartmentalization

Product status

Default status
unaffected

1.0.0 (custom) before 1.0.3
affected

References

spring.io/security/cve-2026-40968

cve.org (CVE-2026-40968)

nvd.nist.gov (CVE-2026-40968)

Download JSON