← Vulnerability feed

Vulnerability record · CVE-2026-22739 · published 24 March 2026

CVE-2026-22739: Vmware spring cloud config path traversal vulnerability

Vmware · Spring Cloud Config

Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configured search directories.This issue affects Spring Cloud: from 3.1.X before 3.1.13, from 4.1.X before 4.1.9, from 4.2.X before 4.2.3, from 4.3.X before 4.3.2, from 5.0.X before 5.0.2.

8.6 CVSS 3.1 High EPSS 1.2% · top 32.5% CWE-22 · Path traversal Undergoing Analysis
8.6CVSS 3.1 base score
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
4 Sep 2026Last modified by NVD

Description

Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configured search directories.This issue affects Spring Cloud: from 3.1.X before 3.1.13, from 4.1.X before 4.1.9, from 4.2.X before 4.2.3, from 4.3.X before 4.3.2, from 5.0.X before 5.0.2.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-22739 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2020-5410Spring Cloud Config Server path traversal exposes arbitrary filesSpring Cloud Config Server versions 2.2.x before 2.2.3, 2.1.x before 2.1.9, and older unsupported releases serve arbitrary configuration files via th…KEVEPSS 96%analysed9.8CVE-2026-47837Vmware spring cloud config missing authentication for critical function vulnerabilityMissing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /mon…EPSS 0.55%9.1CVE-2026-40982Vmware spring cloud config path traversal vulnerabilitySpring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or …EPSS 0.82%8.1CVE-2026-47836Vmware spring cloud config toctou race condition vulnerabilityThe base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to tim…EPSS 0.22%8.1CVE-2026-41002Vmware spring cloud config toctou race condition vulnerabilityThe base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git repositories to is susceptible to t…EPSS 0.22%7.5CVE-2026-47894Vmware spring cloud config vulnerabilitySpring Cloud Config Server native environment repository allows exposure of configuration files outside of the configured repository path. Spring Clo…EPSS 0.49%7.5CVE-2026-40981Vmware spring cloud config insecure direct object reference vulnerabilityWhen using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially expos…EPSS 0.48%6.5CVE-2020-5405Spring Cloud Config Server path traversal in config file servingSpring Cloud Config Server versions 2.2.x before 2.2.2, 2.1.x before 2.1.7, and older unsupported releases can be made to serve arbitrary configurati…EPSS 69%analysed

Source: NIST National Vulnerability Database (record CVE-2026-22739), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.