CVE-2026-2817 Details
Description
Use of insecure directory in Spring Data Geode snapshot import extracts archives into predictable, permissive directories under the system temp location. On shared hosts, a local user with basic privileges can access another user’s extracted snapshot contents, leading to unintended exposure of cache data.
A vulnerability in Spring Data Geode allows for the extraction of snapshot archives into predictable and permissive directories within the system's temporary location. This issue is present in Spring Data Geode versions 2.0.0 prior to 2.7.18 and versions 1.7.0 through 2.2.13. On shared hosting environments, a local user with basic privileges could access another user's extracted snapshot contents, leading to unintended exposure of cache data.
Users can upgrade to the Never-Ending Support (NES) version for Spring, available through HeroDevs, to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 19, 2026CISA-ADP
Assessed Feb 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.herodevs.com/vulnerability-directory/cve-2026-2817 | HeroDevs | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-378 | Creation of Temporary File With Insecure Permissions | HeroDevs |
| CWE-379 | Creation of Temporary File in Directory with Insecure Permissions | HeroDevs |
| CWE-538 | Insertion of Sensitive Information into Externally-Accessible File or Directory | HeroDevs |
Affected Products
| Product | Versions |
|---|---|
| Spring Data Geode | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | HeroDevs |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 19, 2026 | New CVE Received | HeroDevs |
Volerion