SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-47861

MEDIUM · CVSS 6.3 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

An unauthenticated remote attacker can exploit a vulnerability in the Spring Integration UDP inbound adapter by sending a single UDP packet, allowing them to direct the server to emit outbound UDP datagrams to any internal or external host and port. This could lead to unauthorized data exfiltration or service disruption. Organizations using affected versions of Spring Integration should prioritize patching to mitigate potential risks associated with this vulnerability.

CVE
CVE-2026-47861
Severity
MEDIUM
CVSS
6.3
EPSS
0.25%

Original NVD Description

An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to emit an outbound UDP datagram to an arbitrary internal or external host and port of the attacker's choosing. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier

Related CVEs

Other vulnerabilities affecting the same vendor(s)