SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-47894

MEDIUM · CVSS 4.9 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Spring Cloud Config Server is vulnerable due to improper handling of native environment repositories, which can lead to the exposure of sensitive configuration files outside the designated repository path. This vulnerability could potentially allow unauthorized access to critical configuration data, posing a risk to application security. Organizations using affected versions of Spring Cloud Config should prioritize remediation to mitigate potential data leaks.

CVE
CVE-2026-47894
Severity
MEDIUM
CVSS
4.9
EPSS
0.32%

Original NVD Description

Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the configured repository path. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14 and earlier

Related CVEs

Other vulnerabilities affecting the same vendor(s)