SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-47836

HIGH · CVSS 7.2 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Spring Cloud Config Server is vulnerable to time-of-check-time-of-use (TOCTOU) attacks due to improper handling of the base directory used for cloning SVN repositories. This vulnerability could allow an attacker to manipulate files in the directory before they are accessed, potentially leading to unauthorized access or code execution. Organizations using affected versions of Spring Cloud Config should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-47836
Severity
HIGH
CVSS
7.2
EPSS
0.14%

Original NVD Description

The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14 and earlier

Related CVEs

Other vulnerabilities affecting the same vendor(s)