« Volver al listado

CVE-2026-22739

Estado: En análisisAlta (8.6)—

Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configured search directories.This issue affects Spring Cloud: from 3.1.X before 3.1.13, from 4.1.X before 4.1.9, from 4.2.X before 4.2.3, from 4.3.X before 4.3.2, from 5.0.X before 5.0.2.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Acceso de red sin autenticación (AV:N/PR:N) a servidor Config expuesto; path traversal (CWE-22) permite leer archivos del sistema de ficheros local fuera de directorios permitidos.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-22739",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-22739",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-03-24T14:40:20.315216Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@vmware.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.6,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4.7,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "Spring",
          "product": "Spring Cloud",
          "versions": [
            {
              "status": "affected",
              "version": "3.1.x",
              "lessThan": "3.1.13",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.1.x",
              "lessThan": "4.1.9",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.2.x",
              "lessThan": "4.2.3",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.3.x",
              "lessThan": "4.3.2",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "5.0.x",
              "lessThan": "5.0.2",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-03-24T01:17:00.910",
  "references": [
    {
      "url": "https://spring.io/security/cve-2026-22739",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@vmware.com"
    }
  ],
  "vulnStatus": "Undergoing Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configured search directories.This issue affects Spring Cloud: from 3.1.X before 3.1.13, from 4.1.X before 4.1.9, from 4.2.X before 4.2.3, from 4.3.X before 4.3.2, from 5.0.X before 5.0.2."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad en Spring Cloud al sustituir el parámetro de perfil de una solicitud realizada al Spring Cloud Config Server configurado para el sistema de archivos nativo como backend, porque era posible acceder a archivos fuera de los directorios de búsqueda configurados. Este problema afecta a Spring Cloud: desde 3.1.X antes de 3.1.13, desde 4.1.X antes de 4.1.9, desde 4.2.X antes de 4.2.3, desde 4.3.X antes de 4.3.2, desde 5.0.X antes de 5.0.2."
    }
  ],
  "lastModified": "2026-09-04T20:04:45.163",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:spring_cloud_config:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2FA3D9C4-2F28-4618-BE23-D842BA731B5A",
              "versionEndExcluding": "3.1.13"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_cloud_config:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D34AA749-B195-4004-8408-F60B146B7250",
              "versionEndExcluding": "4.1.9",
              "versionStartIncluding": "4.1.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_cloud_config:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "535D6C3E-D8E8-4B5F-8F3B-76D7453C8C03",
              "versionEndExcluding": "4.2.6",
              "versionStartIncluding": "4.2.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_cloud_config:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "836857C0-8E64-4D34-BBE0-07D31F4D7AAB",
              "versionEndExcluding": "4.3.2",
              "versionStartIncluding": "4.3.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_cloud_config:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C28EB16B-C0CB-42F7-A158-D8E72E3A7208",
              "versionEndExcluding": "5.0.2",
              "versionStartIncluding": "5.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@vmware.com"
}