← Browse

CVE-2026-47836

Medium

Elevated severity or exploit probability.

CVSS base
7.2 HIGH
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
EPSS — probability of exploitation (30 days)
0.1%
3.9th percentile
CISA KEV
Not listed
Weakness / dates
CWE-367
Published 2026-08-26 · modified 2026-09-04

CVSS breakdown

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N

Attack VectorLLocal
Attack ComplexityHHigh
Privileges RequiredHHigh
User InteractionNNone
ScopeCChanged
ConfidentialityHHigh
IntegrityHHigh
AvailabilityNNone

Timeline

Description

The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14 and earlier

Affected

vmware

References

Official: NVD · CVE.org