« Back to list

Vmware

Vmware Data Geode: vulnerabilities and CVEs

Vmware Data Geode has 2 published vulnerabilities, 2 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs2
Last 12 months2
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-2818High (8.2)0.38%—Feb 20, 2026
A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on…
CVE-2026-2817Medium (4.8)0.14%—Feb 19, 2026
Use of insecure directory in Spring Data Geode snapshot import extracts archives into predictable, permissive directories under the system temp location. On shared hosts, a local user with basic privileges can access…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1203 Exploitation for Client Execution1
  2. T1565.001 Stored Data Manipulation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Vmware