{"id":"CVE-2026-22739","title":"Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configu…","summary":"Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configu…","severity":"high","cvss":8.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L","cwe":["CWE-22"],"vendor":"vmware","product":"spring_cloud_config","affected":["spring_cloud_config < 3.1.13","spring_cloud_config >= 4.1.0, < 4.1.9","spring_cloud_config >= 4.2.0, < 4.2.6","spring_cloud_config >= 4.3.0, < 4.3.2","spring_cloud_config >= 5.0.0, < 5.0.2"],"patched":["spring_cloud_config 5.0.2"],"published":"2026-03-24","updated":"2026-09-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-22739","references":[{"url":"https://spring.io/security/cve-2026-22739","label":"security@vmware.com"}],"tags":["nvd","exploit-available"],"epss":0.0122,"epssPercentile":0.67383,"ingestedAt":"2026-09-04T20:27:15.271Z","exploits":{"nuclei":["CVE-2026-22739"],"checkedAt":"2026-09-24T07:53:00.797Z"},"exploitAvailable":true,"slug":"CVE-2026-22739","body":"## Overview\n\nVulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configured search directories.This issue affects Spring Cloud: from 3.1.X before 3.1.13, from 4.1.X before 4.1.9, from 4.2.X before 4.2.3, from 4.3.X before 4.3.2, from 5.0.X before 5.0.2.\n\n## Affected\n\n- `spring_cloud_config < 3.1.13`\n- `spring_cloud_config >= 4.1.0, < 4.1.9`\n- `spring_cloud_config >= 4.2.0, < 4.2.6`\n- `spring_cloud_config >= 4.3.0, < 4.3.2`\n- `spring_cloud_config >= 5.0.0, < 5.0.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `spring_cloud_config 5.0.2`","depth":"midnight","depthScore":60,"depthScoreParts":{"impact":47.3,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[{"seq":5012,"id":"CVE-2026-22739","ts":1788887228269,"field":"exploit_available","old":"false","new":"true"},{"seq":3895,"id":"CVE-2026-22739","ts":1788886359278,"field":"exploit_available","old":"true","new":"false"},{"seq":2717,"id":"CVE-2026-22739","ts":1788883024969,"field":"exploit_available","old":"false","new":"true"},{"seq":1746,"id":"CVE-2026-22739","ts":1788882428953,"field":"exploit_available","old":"true","new":"false"},{"seq":852,"id":"CVE-2026-22739","ts":1788881862442,"field":"exploit_available","old":"false","new":"true"}]}