SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-47852

HIGH · CVSS 7.5 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A local attacker on a multi-user host can exploit a vulnerability in Spring AI versions 1.0.0 to 2.0.0 by pre-creating a deterministic cache path to inject a malicious ONNX model file. This could lead to unauthorized execution of arbitrary code, potentially compromising the integrity and confidentiality of the affected system. Organizations using these versions of Spring AI, especially in multi-user environments, should prioritize patching to mitigate this high-severity risk.

CVE
CVE-2026-47852
Severity
HIGH
CVSS
7.5
EPSS
0.20%

Original NVD Description

A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9

Related CVEs

Other vulnerabilities affecting the same vendor(s)