CVE-2026-22739Patch(vmware / spring_cloud_config)

LOWCVSS 8.6 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch vmware spring_cloud_config systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configured search directories.This issue affects Spring Cloud: from 3.1.X before 3.1.13, from 4.1.X before 4.1.9, from 4.2.X before 4.2.3, from 4.3.X before 4.3.2, from 5.0.X before 5.0.2.

2.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • spring_cloud_config

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 15 mentions across 7 observed days
  • Momentum state: declining

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 4 classified signals
  • Peaked 6d ago at 6 mentions (2026-03-24); latest day: 1
  • 15 total mentions across 7 days

Affected systems

Vendors
Products
spring_cloud_config

Deep dive

Activity timeline15 mentions / 7d
02356Mentions · 2026-03-24: 6Mentions · 2026-03-25: 3Mentions · 2026-03-27: 2Mentions · 2026-03-29: 1Mentions · 2026-03-30: 1Mentions · 2026-03-31: 1Mentions · 2026-04-01: 1PoC Mentioned / Linked · 2026-03-30: 1Patch / Workaround · 2026-03-24: 3Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-03-29: 1Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-24: 3Technical Details · 2026-03-25: 1Technical Details · 2026-03-30: 1Technical Details · 2026-04-01: 103-2403-2503-2703-2903-3003-3104-01
Signal classification3 categories
Patch
746.7%
Disclosure
426.7%
General
426.7%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-03-246
Disclosure1General2Patch3
2026-03-253
Disclosure1General1Patch1
2026-03-272
General1Patch1
2026-03-291
Patch1
2026-03-301
Disclosure1
2026-03-311
Patch1
2026-04-011
Disclosure1
Full discourse15 posts
  • V4bel@v4bel
    Disclosure

    Here are some Spring vulns (AI slops) I found while casually testing my AI auditing pipeline: CVE-2026-22738: Spring AI SimpleVectorStore SpEL Injection RCE CVE-2026-22742: Spring AI Bedrock SSRF via Unvalidated Media URL CVE-2026-22744: Spring AI RedisVectorStore TAG Filter Injection CVE-2026-22739: Spring Cloud Config Server Profile Path Traversal & SSRF CVE-2026-... Just RCE. Nothing technically impressive. Took me two days 😅

    Post summary

    User lists several recent Spring CVEs with brief type labels, providing initial disclosure information but no PoC, exploit code, patch, or evidence of active exploitation.

    04046255.0K
    1.5K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-22739 - high 🚨 Spring Cloud Config Server - Path Traversal > Spring Cloud 3.1.x < 3.1.13, 4.1.x < 4.1.9, 4.2.x < 4.2.3, 4.3.x < 4.3.2, and 5.0.x <... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-22739 @pdnuclei #NucleiTemplates #cve

    Post summary

    High‑severity Path Traversal vulnerability in multiple Spring Cloud Config Server versions, with affected ranges and a link to further details.

    00074255
    960 followersView on X
  • Gray Hats@the_yellow_fall
    Disclosure

    Spring Cloud Config faces a high-severity CVSS 8.6 flaw (CVE-2026-22739). Attackers can manipulate profiles to access local files or launch SSRF attacks. #SpringCloud #CVE #CyberSecurity #InfoSec #CloudSecurity #Java #SSRF #PatchAlert #Vulnerability https://securityonline.info/spring-cloud-config-vulnerability-cve-2026-22739-ssrf-traversal/ https://t.co/fgIsUr5iZJ

    Post summary

    The tweet announces a new high‑severity vulnerability (CVE‑2026‑22739) in Spring Cloud Config, noting its impact (local file access and SSRF) but provides no PoC, exploit code, or patch information.

    01063433
    10.9K followersView on X
  • Daniel Simelka@dsimelka
    Patch

    Spring Cloud Config 5.0.2, 4.3.2, 4.2.6, 4.1.9, 3.1.13 Released, includes fix for CVE-2026-22739 https://dy.si/DVeSc https://t.co/teXiJHTYuW

    Post summary

    The message announces a new Spring Cloud Config release that includes a fix for CVE-2026-22739.

    0002031
    718 followersView on X
  • Cloud Virtues@CloudVirtues
    Patch

    Spring Cloud Config 5.0.2, 4.3.2, 4.2.6, 4.1.9, 3.1.13 Released, includes fix for CVE-2026-22739 https://dy.si/bzi5U12 https://t.co/idtsxZkw39

    Post summary

    Spring Cloud Config releases 5.0.2, 4.3.2, 4.2.6, 4.1.9, and 3.1.13 include a fix for CVE-2026-22739; no exploit or technical details are provided.

    0002025
    10 followersView on X
  • Dr. Siraj Dokadia@SirajD_Official
    Patch

    Spring Cloud Config 5.0.2, 4.3.2, 4.2.6, 4.1.9, 3.1.13 Released, includes fix for CVE-2026-22739 https://dy.si/76MENU https://t.co/c8Zg9bkmDX

    Post summary

    Spring Cloud Config released several versions that include a fix for CVE-2026-22739.

    0001031
    15 followersView on X
  • キタきつね@foxbook
    Disclosure

    Spring Cloud Configの重大な脆弱性により、ファイル漏洩とSSRF攻撃が発生 High-Severity Spring Cloud Config Flaw Triggers File Leaks and SSRF #DailyCyberSecurity (Mar 24) https://securityonline.info/spring-cloud-config-vulnerability-cve-2026-22739-ssrf-traversal/

    Post summary

    The post announces a newly disclosed high‑severity flaw in Spring Cloud Config that causes file leaks and SSRF vulnerabilities, but does not provide PoC, exploit code, patch details, or evidence of active exploitation.

    00010248
    4.8K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en productos Spring ❗ CVE-2026-22739 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-spring-3/ https://t.co/My3d67rZUq

    Post summary

    The tweet merely alerts to CVE‑2026‑22739 in Spring products and links to another page for details, without any explicit technical, exploit, or patch information.

    00000126
    6.6K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-22739 📊 Severity: 8.6 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-22739 #CVE-2026-22739 #CVE #High  #CyberSecurity #InfoSec https://t.co/qTTbxfY8gK

    Post summary

    The text is a brief CVE alert for CVE-2026-22739 with high severity, but it does not provide additional technical detail, PoC, or exploitation information.

    0000034
    114 followersView on X
  • aaa ppp@aaappp75764701
    Patch

    Spring Cloud Config 5.0.2, 4.3.2, 4.2.6, 4.1.9, 3.1.13 Released, includes fix for CVE-2026-22739 https://dy.si/frdeUm2 https://t.co/uZI8SnVLpV

    Post summary

    The text announces new Spring Cloud Config releases that include a fix for CVE-2026-22739, with no mention of PoC, exploit code, or active exploitation.

    0000034
    1 followersView on X
  • Marco Scandaletti@scandaletti
    Patch

    Spring Cloud Config 5.0.2, 4.3.2, 4.2.6, 4.1.9, 3.1.13 Released, includes fix for CVE-2026-22739 https://dy.si/ftcBMR https://t.co/J87MRmO11K

    Post summary

    The tweet informs that Spring Cloud Config versions 5.0.2, 4.3.2, 4.2.6, 4.1.9, and 3.1.13 have been released, including a fix for CVE-2026-22739.

    0000034
    243 followersView on X
  • John Arrasjid@vcdx001
    Patch

    Spring Cloud Config 5.0.2, 4.3.2, 4.2.6, 4.1.9, 3.1.13 Released, includes fix for CVE-2026-22739 https://dy.si/1yH4M https://t.co/qjm21Oc3QX

    Post summary

    The tweet announces new Spring Cloud Config releases that incorporate a patch for CVE-2026-22739.

    0000044
    4.9K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-22739 Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a … https://www.cve.org/CVERecord?id=CVE-2026-22739

    Post summary

    The statement merely references CVE‑2026‑22739 with a brief note about a vulnerability scenario and links to the CVE record, offering no further technical or operational details.

    00000132
    56.8K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-22739: HIGH] Critical vulnerability in Spring Cloud Config allows file access outside designated directories. Ensure your Spring Cloud version is updated to 3.1.13, 4.1.9, 4.2.3, 4.3.2, or 5.0.2 to...#cve,CVE-2026-22739,#cybersecurity https://cvefind.com/CVE-2026-22739

    Post summary

    The post highlights a high-severity CVE-2026-22739 in Spring Cloud Config that permits directory traversal, and advises updating to the listed patched versions to resolve the vulnerability.

    0000048
    606 followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🟠 CVE-2026-22739 - High Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was p... https://www.thehackerwire.com/vulnerability/CVE-2026-22739/ https://t.co/I2SPNYCzro

    Post summary

    The tweet announces a high‑severity CVE‑2026‑22739 affecting Spring Cloud Config Server by abusing profile parameter substitution, but offers only a brief technical description without evidence of exploitation, PoC, or patch information.

    0000034
    145 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarespring_cloud_config---

Explore more