File Permission Vulnerability in Spring Integration by Pivotal
CVE-2026-59292

3.2LOW

Key Information:

Vendor

Spring

Vendor
CVE Published:
27 August 2026

What is CVE-2026-59292?

The PropertiesPersistingMetadataStore in Spring Integration has a security issue where it persists its state to a file located in the temporary directory with world-readable permissions. This breach allows unauthorized users to access sensitive metadata, potentially leading to data exposure and breaches in confidentiality. The issue affects multiple versions of Spring Integration, prompting users to take immediate action to secure their systems.

Affected Version(s)

Spring Integration 7.1.0

Spring Integration 7.0.0 <= 7.0.5

Spring Integration 6.5.0 <= 6.5.10

References

CVSS V3.1

Score:
3.2
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.