Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40542

29
FAUCET Score

BRIEFING NOTE CVE-2026-40542 is a critical authentication bypass vulnerability in Apache HttpClient version 5.6 that permits attackers to circumvent SCRAM-SHA-256 mutual authentication verification. This flaw allows clients to accept authentication without completing proper verification steps, potentially enabling unauthorized access or man-in-the-middle attacks against applications using the affected library. The vulnerability carries a CVSS v3.1 severity score of 7.3 (HIGH) with a network-based attack vector requiring no authentication or user interaction. The attack is straightforward to execute (low complexity) and results in confidentiality, integrity, and availability impacts across the affected system. Immediate patching to Apache HttpClient version 5.6.1 is strongly recommended to remediate the issue. There is no evidence of active exploitation in the wild, as this vulnerability is not listed in the Known Exploited Vulnerabilities (KEV) database and remains inactive on industry hotlists. However, the FAUCET Risk Score of 47.0/100 indicates moderate concern warranting prioritized patch deployment. Organizations running Apache HttpClient 5.6 should apply updates promptly to prevent potential exploitation before threat actors develop and distribute exploit code.

Impacted Technologies

VendorProductVersion(s)CPE
5.6CPE matchmatch criteria
cpe:2.3:a:apache:httpclient:5.6:-:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.3HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
3.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.46%
Probability of exploitation in next 30 days
EPSS Percentile
37.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0046 is in the 16th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

mavenpatch availablevia ghsa
Product: org.apache.httpcomponents.client5:httpclient5Fixed in: 5.6.1

Vendor Advisories (1)

mavenGHSA-v468-qcjx-r72whigh

Apache HttpClient accepts SCRAM-SHA-256 authentication without proper mutual authentication verification

Apr 22, 2026

References

access.redhat.com / security/cve/CVE-2026-40542
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-40542.json
openwall.com / lists/oss-security/2026/04/22/5
Mailing ListThird Party Advisory
lists.apache.org / thread/tfmgv86xr0z1y096vs3z0y315t1v3o97
Mailing ListVendor Advisory