CVE-2026-47862: VMware Spring Integration
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE (the default) can cause the resulting .zip archive to be written to an arbitrary filesystem path outside the configured workDirectory. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12
Affected products
- VMware Spring Integration: from 6.4.0, before 6.4.13 (fixed in 6.4.13); from 6.5.0, before 6.5.11 (fixed in 6.5.11); from 7.0.0, before 7.0.5.1 (fixed in 7.0.5.1); from 7.1.0, before 7.1.0.1 (fixed in 7.1.0.1)
Published 2026-08-27. Last modified 2026-09-02.