PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-47852 Spring CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-27T01:17:32.320Z and has not been modified since then. CVE-2026-47852 allows local attackers on multi-user hosts to exploit Spring AI by pre-creating a deterministic cache path and planting a malicious ONNX model file, affecting versions 1.0.0-1.0.9, 1.1.0-1.1.8, and 2.0.0. This vulnerability can be mitigated by verifying and applying vendor patches, restricting local access to sensitive host resources, and monitoring for suspicious ONNX model file creations. Users of Spring AI versions 1.0.0-1.0.9, 1.1.0-1.1.8, and 2.0.0, especially those with multi-user hosts, should verify and apply patches or mitigations.

Vendor
Spring
Product
Spring AI
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-27
Original CVE updated
2026-09-04
Advisory published
2026-08-27
Advisory updated
2026-09-04

Who should care

Users of Spring AI versions 1.0.0-1.0.9, 1.1.0-1.1.8, and 2.0.0, especially those with multi-user hosts, should verify and apply patches or mitigations. This includes operators, platform administrators, vulnerability management teams, and security teams who need to assess the impact of this vulnerability on their environments and take appropriate action.

Technical summary

CVE-2026-47852 allows local attackers on multi-user hosts to exploit Spring AI by pre-creating a deterministic cache path and planting a malicious ONNX model file, affecting versions 1.0.0-1.0.9, 1.1.0-1.1.8, and 2.0.0. This vulnerability can be mitigated by verifying and applying vendor patches, restricting local access to sensitive host resources, and monitoring for suspicious ONNX model file creations.

Defensive priority

Local attackers on multi-user hosts may attempt to exploit this vulnerability; verify and apply vendor patches.

Recommended defensive actions

  • Verify affected Spring AI versions (1.0.0-1.0.9, 1.1.0-1.1.8, 2.0.0) are patched or mitigated
  • Restrict local access to sensitive host resources
  • Monitor for suspicious ONNX model file creations

Evidence notes

The CVE-2026-47852 record indicates a local attacker can pre-create a deterministic cache path and plant a malicious ONNX model file affecting Spring AI versions 1.0.0-1.0.9, 1.1.0-1.1.8, and 2.0.0. This vulnerability allows for potential exploitation on multi-user hosts. Defenders should verify affected versions, review system logs for suspicious activity, and ensure proper patching and mitigation strategies are in place.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-47852 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-47852

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-47852 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47852

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.