CVE 7.1 HIGH

Remote-file synchronizer in Spring Integration writes server-supplied filename under localDirectory without canonicalization_CVE-2026-40987

7.1 / 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L

Description

A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled content.

Affected versions:
Spring Integration 7.0.0 through 7.0.4; 6.5.0 through 6.5.8; 6.4.0 through 6.4.11; 6.3.0 through 6.3.14; 5.5.0 through 5.5.20.

Basic Information

ID CVE-2026-40987
Source vmware
Published Jun 11, 2026 at 05:03

Affected Product

Vendor Spring
Product Spring Integration
Version 7.0.0
Affected Versions Spring Spring Integration 7.0.0
Spring Spring Integration 6.5.0
Spring Spring Integration 6.4.0
Spring Spring Integration 6.3.0
Spring Spring Integration 5.5.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.