CVE-2026-40979

medium VMware
CVSS v3 Base Score
6.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
EPSS Score
0.0%
Exploitation probability in 30 days
Top 98% most likely to be exploited
Attack Characteristics
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Confidentiality
Low
Integrity
High
Availability
None
Published: April 28, 2026 (15 days ago)
Last Modified: April 29, 2026
Vendor: VMware
Source: NVD

Description

In Spring AI, having access to a shared environment can expose the ONNX model used by the application. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5)

CWE

CWE-377

Affected Products

vmware spring ai

References