Spring Cloud Config Server - Path Traversal
CVE-2026-22739
Verified
Description
Spring Cloud 3.1.x < 3.1.13, 4.1.x < 4.1.9, 4.2.x < 4.2.3, 4.3.x < 4.3.2, and 5.0.x < 5.0.2 contain a path traversal caused by profile parameter substitution in Config Server using native file system backend, letting attackers access files outside configured directories, exploit requires crafted request.
Severity
High
CVSS Score
8.6
Exploit Probability
1%
Affected Product
spring_cloud_config
Published Date
March 29, 2026
Template Author
0x_akoko, vulnh0lic
CVE-2026-22739.yaml
8.6Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
CVE ID:
cve-2026-22739
CWE ID:
cwe-22
Remediation Steps
"Upgrade to versions 3.1.13, 4.1.9, 4.2.3, 4.3.2, or 5.0.2 or later.