Arbitrary File Write Vulnerability in Spring Framework by Pivotal
CVE-2026-40987

7.1HIGH

Key Information:

Vendor

Spring

Vendor
CVE Published:
11 June 2026

What is CVE-2026-40987?

A vulnerability exists in the Spring Framework that allows a malicious or compromised FTP/SFTP/SMB server to write arbitrary files to any location on a client's filesystem. This can occur outside of the designated local directory and can include content controlled by the attacker. This poses significant risks to the integrity and confidentiality of file systems used by applications interacting with affected versions of the Spring Framework.

Affected Version(s)

Spring Integration 7.0.0 < 7.0.4.1

Spring Integration 6.5.0 < 6.5.8.1

Spring Integration 6.4.0 < 6.4.12

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.