PT-2026-20882 · Vmware · Spring Data Geode

Published

2026-02-19

·

Updated

2026-02-23

·

CVE-2026-2817

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Spring Data Geode (affected versions not specified)
Description The software has a flaw related to insecure directory usage during snapshot imports. Specifically, archives are extracted into predictable and overly permissive directories within the system's temporary location. This can lead to unauthorized access to cache data on shared hosts, as a local user with limited privileges may be able to access the extracted contents of another user's snapshot.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2026-2817

Affected Products

Spring Data Geode