PatchSiren cyber security CVE debrief
CVE-2026-50267 SteeltoeOSS CVE debrief
Steeltoe Configuration Abstractions versions 4.0.0 through 4.1.0 are vulnerable to a medium-severity issue (CVSS score 4.7) where MySQL or PostgreSQL service bindings from `VCAP_SERVICES` including TLS client credentials are written to temporary files in `Path.GetTempPath()` with world-readable permissions (mode `0644`) on Linux systems. These files are never deleted and can be accessed by other processes. The credentials are also stored in `/proc/<pid>/environ` with mode `0400`. Version 4.2.0 of Steeltoe.Configuration.Abstractions patches this issue.
- Vendor
- SteeltoeOSS
- Product
- Steeltoe.Configuration.Abstractions
- CVSS
- MEDIUM 4.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-17
- Original CVE updated
- 2026-06-22
- Advisory published
- 2026-06-17
- Advisory updated
- 2026-06-22
Who should care
Users of Steeltoe Configuration Abstractions versions 4.0.0 through 4.1.0, especially those deploying on Linux containers, should be aware of this vulnerability. Developers and administrators responsible for cloud-native applications using Steeltoe should assess the risk and apply the patch or mitigation measures.
Technical summary
In Steeltoe.Configuration.Abstractions 4.0.0 through 4.1.0, when MySQL or PostgreSQL service bindings from `VCAP_SERVICES` include TLS client credentials, the Connectors library writes those credentials to temporary files in `Path.GetTempPath()` using `File.CreateText`. On Linux, `File.CreateText` creates files with mode `0644` (world-readable) under the process umask. The files are never deleted, and the same key material is protected at mode `0400` in `/proc/<pid>/environ`. Steeltoe.Configuration.Abstractions version 4.2.0 patches the issue by properly handling credentials.
Defensive priority
Medium
Recommended defensive actions
- Upgrade to Steeltoe.Configuration.Abstractions version 4.2.0 or later.
- If an immediate upgrade is not possible, prevent other processes from running in the container under a different UID with access to `/tmp`.
- Review and adjust file permissions and umask settings for the application process.
- Monitor temporary file directories for suspicious activity.
- Implement additional logging and auditing for sensitive credential handling.
- Consider using secure storage mechanisms for sensitive credentials.
Evidence notes
The vulnerability is confirmed through analysis of the Steeltoe Configuration Abstractions codebase and verification of the patch in version 4.2.0. The issue is reported by an unknown vendor and confirmed by the Steeltoe OSS community. References include commits and advisories from the SteeltoeOSS GitHub repository.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-50267 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-50267
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-50267 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-50267
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/SteeltoeOSS/Steeltoe/commit/8dd97cc6c4b184121a4bd1f92f9ac16918433471
-
Source reference
Unverified legacy reference
URL: https://github.com/SteeltoeOSS/security-advisories/security/advisories/GHSA-rxrh-4j9h-xgg9
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.