CVE-2026-2817

Use of insecure directory in Spring Data Geode snapshot import extracts archives into predictable, permissive directories under the system temp location. On shared hosts, a local user with basic privileges can access another user’s extracted snapshot contents, leading to unintended exposure of cache data.
Configurations

No configuration.

History

19 Feb 2026, 18:25

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-19 18:25

Updated : 2026-02-20 13:49


NVD link : CVE-2026-2817

Mitre link : CVE-2026-2817

CVE.ORG link : CVE-2026-2817


JSON object : View

Products Affected

No product.

CWE
CWE-378

Creation of Temporary File With Insecure Permissions

CWE-379

Creation of Temporary File in Directory with Insecure Permissions

CWE-538

Insertion of Sensitive Information into Externally-Accessible File or Directory