Configuration Exposure in Spring Cloud Config Server by Spring
CVE-2026-47894
4.9MEDIUM
What is CVE-2026-47894?
The Spring Cloud Config Server has a vulnerability that can lead to the exposure of sensitive configuration files if the repository path is not configured properly. This allows unauthorized access to potentially sensitive information stored in configuration files. Multiple versions of Spring Cloud Config from version 5.0.0 to 3.1.14 are affected, underscoring the need for immediate mitigation strategies to safeguard sensitive data.
Affected Version(s)
Spring Cloud Config 5.0.0 <= 5.0.4
Spring Cloud Config 4.3.0 <= 4.3.4
Spring Cloud Config 4.0.0 <= 4.2.8
