Local User Vulnerability in Spring Integration by Pivotal Software
CVE-2026-59311

6.8MEDIUM

Key Information:

Vendor

Spring

Vendor
CVE Published:
27 August 2026

What is CVE-2026-59311?

A vulnerability exists that allows a local unprivileged user on the same host to redirect the output of Zip/UnZip transformer operations. This is achieved by creating a symbolic link at /tmp/ziptransformer before the application starts, allowing the user to control the destination of the output files. Affected versions of Spring Integration include 7.1.0, 7.0.0 to 7.0.5, and 6.4.0 to 6.5.10, exposing potential risks to system integrity and security.

Affected Version(s)

Spring Integration 7.1.0

Spring Integration 7.0.0 <= 7.0.5

Spring Integration 6.5.0 <= 6.5.10

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.