SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-59311

MEDIUM · CVSS 6.8 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A local unprivileged user can exploit a symlink vulnerability in Spring Integration versions 6.4.0 to 7.1.0, allowing them to redirect Zip/UnZip transformer output to a directory of their choice. This could lead to unauthorized data exposure or manipulation. Organizations using affected versions should prioritize patching to mitigate potential risks associated with this vulnerability.

CVE
CVE-2026-59311
Severity
MEDIUM
CVSS
6.8
EPSS
0.35%

Original NVD Description

A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a directory of their choosing by pre-creating /tmp/ziptransformer as a symlink before the application starts. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12

Related CVEs

Other vulnerabilities affecting the same vendor(s)