BRIEFING NOTE CVE-2026-40542 is a critical authentication bypass vulnerability in Apache HttpClient version 5.6 that permits attackers to circumvent SCRAM-SHA-256 mutual authentication verification. This flaw allows clients to accept authentication without completing proper verification steps, potentially enabling unauthorized access or man-in-the-middle attacks against applications using the affected library. The vulnerability carries a CVSS v3.1 severity score of 7.3 (HIGH) with a network-based attack vector requiring no authentication or user interaction. The attack is straightforward to execute (low complexity) and results in confidentiality, integrity, and availability impacts across the affected system. Immediate patching to Apache HttpClient version 5.6.1 is strongly recommended to remediate the issue. There is no evidence of active exploitation in the wild, as this vulnerability is not listed in the Known Exploited Vulnerabilities (KEV) database and remains inactive on industry hotlists. However, the FAUCET Risk Score of 47.0/100 indicates moderate concern warranting prioritized patch deployment. Organizations running Apache HttpClient 5.6 should apply updates promptly to prevent potential exploitation before threat actors develop and distribute exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.6CPE matchmatch criteria | cpe:2.3:a:apache:httpclient:5.6:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.