PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-47862 Vmware CVE debrief

The CVE-2026-47862 vulnerability affects Spring Integration, specifically versions 6.4.0 - 6.4.12, 6.5.0 - 6.5.10, 7.0.0 - 7.0.5, and 7.1.0. An attacker can cause a .zip archive to be written to an arbitrary filesystem path outside the configured workDirectory by setting the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE. Organizations should prioritize patching to prevent potential arbitrary file write vulnerabilities. The CVE record was published on 2026-08-27T01:17:33.313Z and has not been modified since then.

Vendor
Vmware
Product
Spring Integration
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-27
Original CVE updated
2026-09-02
Advisory published
2026-08-27
Advisory updated
2026-09-02

Who should care

Organizations using Spring Integration in their applications, especially those with untrusted input or exposed ZipTransformer instances, should be aware of this vulnerability. They should prioritize patching to prevent potential arbitrary file write vulnerabilities. Security teams and operators managing Spring Integration deployments should review the official advisory and CVE record to validate affected scope, severity, and vendor guidance. Vulnerability management and platform security teams should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified. Monitoring, detection, and logs for exposed assets should be checked for extra review. Exceptions, retesting of remediated assets, and closing the item only after evidence is documented are crucial steps. Asset inventory and source tracking can help in managing the remediation process effectively. Rollback/change windows should be considered for updates. This vulnerability impacts operators, platforms, and security teams managing Spring Integration deployments. Affected deployments should be identified, and owners assigned for follow-up. The official advisory or CVE record should be reviewed to validate affected scope, severity, and vendor guidance. Vendor-supported updates or mitigations should be planned through normal change control where exposure is confirmed. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified. Monitoring, detection, and logs for exposed assets should be checked for extra review. Exceptions, retesting of remediated assets, and closing the item only after evidence is documented are crucial steps. Asset inventory and source tracking can help in managing the remediation process effectively. Rollback/change windows should be considered for updates. Security teams should track exceptions, retest remediated assets, and close the item only after evidence is documented. This vulnerability affects operators, platforms, and security teams managing Spring Integration deployments. The CVE record is

Technical summary

An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE can cause the resulting .zip archive to be written to an arbitrary filesystem path outside the configured workDirectory. This affects Spring Integration versions 6.4.0 - 6.4.12, 6.5.0 - 6.5.10, 7.0.0 - 7.0.5, and 7.1.0. The vulnerability allows for potential arbitrary file write vulnerabilities. Organizations using affected Spring Integration versions should prioritize patching to prevent this vulnerability.

Defensive priority

Organizations using affected Spring Integration versions should prioritize patching to prevent potential arbitrary file write vulnerabilities.

Recommended defensive actions

  • Apply patches for affected Spring Integration versions
  • Restrict access to ZipTransformer with ZipResultType.FILE
  • Monitor for suspicious .zip archive creation
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.

Evidence notes

The CVE record indicates that an attacker can cause a .zip archive to be written to an arbitrary filesystem path outside the configured workDirectory by setting the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE. Affected versions include Spring Integration 6.4.0 - 6.4.12, 6.5.0 - 6.5.10, 7.0.0 - 7.0.5, and 7.1.0.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-47862 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-47862

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-47862 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47862

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.