CVE-2026-40977 | Vmware Spring Boot up to 4.0.5 PID File ApplicationPidFileWriter link following (CNNVD-202604-5558)
A vulnerability was found in Vmware Spring Boot up to 2.7.32/3.3.18/3.4.15/3.5.13/4.0.5. It has been declared as critical. The affected element is the function ApplicationPidFileWriter of the component PID File Handler. The manipulation results in link following.
This vulnerability is cataloged as CVE-2026-40977. The attack must be initiated from a local position. There is no exploit available.
It is recommended to upgrade the affected component.