PatchSiren cyber security CVE debrief
CVE-2026-47852 Spring CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-27T01:17:32.320Z and has not been modified since then. CVE-2026-47852 allows local attackers on multi-user hosts to exploit Spring AI by pre-creating a deterministic cache path and planting a malicious ONNX model file, affecting versions 1.0.0-1.0.9, 1.1.0-1.1.8, and 2.0.0. This vulnerability can be mitigated by verifying and applying vendor patches, restricting local access to sensitive host resources, and monitoring for suspicious ONNX model file creations. Users of Spring AI versions 1.0.0-1.0.9, 1.1.0-1.1.8, and 2.0.0, especially those with multi-user hosts, should verify and apply patches or mitigations.
- Vendor
- Spring
- Product
- Spring AI
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-27
- Original CVE updated
- 2026-09-04
- Advisory published
- 2026-08-27
- Advisory updated
- 2026-09-04
Who should care
Users of Spring AI versions 1.0.0-1.0.9, 1.1.0-1.1.8, and 2.0.0, especially those with multi-user hosts, should verify and apply patches or mitigations. This includes operators, platform administrators, vulnerability management teams, and security teams who need to assess the impact of this vulnerability on their environments and take appropriate action.
Technical summary
CVE-2026-47852 allows local attackers on multi-user hosts to exploit Spring AI by pre-creating a deterministic cache path and planting a malicious ONNX model file, affecting versions 1.0.0-1.0.9, 1.1.0-1.1.8, and 2.0.0. This vulnerability can be mitigated by verifying and applying vendor patches, restricting local access to sensitive host resources, and monitoring for suspicious ONNX model file creations.
Defensive priority
Local attackers on multi-user hosts may attempt to exploit this vulnerability; verify and apply vendor patches.
Recommended defensive actions
- Verify affected Spring AI versions (1.0.0-1.0.9, 1.1.0-1.1.8, 2.0.0) are patched or mitigated
- Restrict local access to sensitive host resources
- Monitor for suspicious ONNX model file creations
Evidence notes
The CVE-2026-47852 record indicates a local attacker can pre-create a deterministic cache path and plant a malicious ONNX model file affecting Spring AI versions 1.0.0-1.0.9, 1.1.0-1.1.8, and 2.0.0. This vulnerability allows for potential exploitation on multi-user hosts. Defenders should verify affected versions, review system logs for suspicious activity, and ensure proper patching and mitigation strategies are in place.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-47852 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-47852
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-47852 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47852
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://spring.io/security/cve-2026-47852
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.