216.73.216.226

CVE-2026-2817

· Published 19/02/2026 18:25 · Modified 20/02/2026 13:49

Labels: CVE-2026-2817 2026-02-1936c7be3b-2937-45df-85ea-ca7133ea542cCVE-2026-2817CWE-378

Essential information

Published
19/02/2026 18:25
Modified
20/02/2026 13:49
Author
Creator
CVSS
4.8 MEDIUM (v3) 4.8 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Use of insecure directory in Spring Data Geode snapshot import extracts archives into predictable, permissive directories under the system temp location. On shared hosts, a local user with basic privileges can access another user’s extracted snapshot contents, leading to unintended exposure of cache data.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
36c7be3b-2937-45df-85ea-ca7133ea542c
NVD
View on NVD

Affected products (CPE)

ProductCPE
spring / spring data geode cpe:2.3:a:spring:spring_data_geode:*:*:*:*:*:*:*:*

References