Threats Tagged 'cve-2026-47862'
View all threats tagged with 'cve-2026-47862'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-47862'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-47862 is a vulnerability in Spring Integration where an attacker able to set the file_name header on a message processed by a ZipTransformer with the default ZipResultType.FILE can cause the resulting ZIP archive to be written outside the intended workDirectory. This can lead to arbitrary file write on the filesystem. Join the discussion | GCVE Database | 08/27/2026, 03:32:58 UTC Added: 08/27/2026, 15:13:09 UTC |
0 CVE-2026-47862 is a path traversal vulnerability in Spring Integration affecting certain versions. An attacker who can control the file_name header on a message processed by the ZipTransformer component with the default ZipResultType.FILE can cause a .zip archive to be written outside the intended working directory. This could lead to unauthorized file writes on the filesystem. The vulnerability affects specific versions of Spring Integration including 6.4.0 through 6.4.12, 6.5.0 through 6.5.10, 7.0.0 through 7.0.5, and exactly version 7.1.0. The CVSS score is 5.4, indicating a medium severity impact. No official patch or remediation information is currently available. Join the discussion | CVE Database V5 | 08/26/2026, 23:28:47 UTC Added: 08/27/2026, 00:38:18 UTC |
Showing 1 to 2 of 2 results