Arbitrary File Write Vulnerability in Spring Integration by Pivotal Software
CVE-2026-47862

5.4MEDIUM

Key Information:

Vendor

Spring

Vendor
CVE Published:
26 August 2026

What is CVE-2026-47862?

An arbitrary file write vulnerability exists in Spring Integration, where an attacker can manipulate the 'file_name' header on a message processed by a ZipTransformer. This flaw allows for the creation of a .zip archive that can be written to any file path outside of the predetermined workDirectory. This could lead to potential exposure of sensitive files or system compromise. It is critical for users of the affected versions to apply necessary mitigations to secure their application.

Affected Version(s)

Spring Integration 7.1.0

Spring Integration 7.0.0 <= 7.0.5

Spring Integration 6.5.0 <= 6.5.10

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.