CVE-2026-41001
CVE-2026-41001 is a medium-severity vulnerability in Vmware Spring Boot with a CVSS 3.x base score of 5.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-377.
Key facts
- Severity: Medium (CVSS 3.x base score 5.3)
- EPSS exploit prediction: 0% (2nd percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-36211
- Weakness: CWE-377
- Affected product: Vmware Spring Boot
- Published:
- Last modified:
Description
Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A local attacker on the same host can pre-create this predictable directory or place a symlink before the application starts. Affected versions: Spring Boot 4.0.0 through 4.0.6; 3.5.0 through 3.5.14; 3.4.0 through 3.4.16; 3.3.0 through 3.3.19; 2.7.0 through 2.7.33.
Frequently asked questions
- What is CVE-2026-41001?
- Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A local attacker on the same host can pre-create this predictable directory or place a symlink before the application starts. Affected versions: Spring Boot 4.0.0 through 4.0.6; 3.5.0 through 3.5.14; 3.4.0 through 3.4.16; 3.3.0 through 3.3.19; 2.7.0 through 2.7.33.
- How severe is CVE-2026-41001?
- CVE-2026-41001 has a CVSS 3.x base score of 5.3, rated medium severity. It is exploitable over local access with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is low, integrity low, and availability low.
- Is CVE-2026-41001 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (2nd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-41001?
- CVE-2026-41001 affects Vmware Spring Boot. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-41001?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-41001 have an EU (EUVD) identifier?
- Yes. CVE-2026-41001 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-36211.
- When was CVE-2026-41001 published?
- CVE-2026-41001 was published on 2026-06-11 and last updated on 2026-09-04.
References
Affected products (1)
- cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*
More vulnerabilities in Vmware Spring Boot
- CVE-2023-20873 — Critical (CVSS 9.8): In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed…
- CVE-2021-26987 — Critical (CVSS 9.8): Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are…
- CVE-2017-8046 — Critical (CVSS 9.8): Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions…
- CVE-2026-40976 — Critical (CVSS 9.1): In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all…
- CVE-2026-22733 — High (CVSS 8.2): Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an…
- CVE-2026-22731 — High (CVSS 8.2): Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an…
All CVEs affecting Vmware Spring Boot →
Other CWE-377 (Insecure Temporary File) vulnerabilities
- CVE-2011-4119 — Critical (CVSS 9.8): caml-light <= 0.75 uses mktemp() insecurely, and also does unsafe things in /tmp during make install.
- CVE-2012-2666 — Critical (CVSS 9.8): golang/go in 1.0.2 fixes all.bash on shared machines. dotest() in src/pkg/debug/gosym/pclntab_test.go creates a…
- CVE-2015-5224 — Critical (CVSS 9.8): The mkostemp function in login-utils in util-linux when used incorrectly allows remote attackers to cause file name…
- CVE-2025-14307 — High (CVSS 8.1): An insecure temporary file creation vulnerability exists in the AutoExtract component of Robocode version 1.9.3.6. The…
- CVE-2023-43498 — High (CVSS 8.1): In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using MultipartFormDataParser creates…
- CVE-2026-79899 — High (CVSS 7.9): Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates…
Browse all CWE-377 (Insecure Temporary File) vulnerabilities →