CVE-2026-41001 Details
Description
Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A local attacker on the same host can pre-create this predictable directory or place a symlink before the application starts. Affected versions: Spring Boot 4.0.0 through 4.0.6; 3.5.0 through 3.5.14; 3.4.0 through 3.4.16; 3.3.0 through 3.3.19; 2.7.0 through 2.7.33.
A vulnerability exists in Spring Boot's ArtemisEmbeddedConfigurationFactory, which uses a fixed path for the embedded Artemis message broker's data directory when no explicit path is set. This predictable directory allows a local attacker on the same host to pre-create the directory or place a symlink before the application starts. Exploitation could lead to hijacking message queue data, injecting malicious messages, or executing code through deserialization attacks via the journal. Affected versions include Spring Boot 4.0.0 through 4.0.6, 3.5.0 through 3.5.14, 3.4.0 through 3.4.16, 3.3.0 through 3.3.19, and 2.7.0 through 2.7.33.
Users should upgrade to Spring Boot versions 4.0.7, 3.5.15, 3.4.17, 3.3.20, or 2.7.34. For Spring Boot 4.0.x and 3.5.x, versions 4.0.6.1 and 3.5.14.1 are available for Enterprise Support Only.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://spring.io/security/cve-2026-41001 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-377 | Insecure Temporary File | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| vmware spring boot | < 2.7.34 >= 3.3.0, < 3.3.20 >= 3.4.0, < 3.4.17 >= 3.5.0, < 3.5.14.1 >= 4.0.0, < 4.0.6.1 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 4, 2026 | Initial Analysis | [email protected] |
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 23, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 11, 2026 | New CVE Received | [email protected] |