CVE-2026-47836: VMware Spring Cloud Config

High severity, CVSS 8.1. EPSS: 0.2% chance of exploitation in the next 30 days.

The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14 and earlier

Affected products

  • VMware Spring Cloud Config: before 3.1.15 (fixed in 3.1.15); from 4.0.0, before 4.2.9 (fixed in 4.2.9); from 4.3.0, before 4.3.5 (fixed in 4.3.5); from 5.0.0, before 5.0.5 (fixed in 5.0.5)

Published 2026-08-26. Last modified 2026-09-04.