CVE-2026-40987
Description
A flaw was found in Spring Integration. A malicious or compromised FTP (File Transfer Protocol), SFTP (SSH File Transfer Protocol), or SMB (Server Message Block) server can exploit this vulnerability. This allows the server to write arbitrary files with attacker-controlled content to any location on the client's filesystem, bypassing the configured local directory restrictions. This could lead to unauthorized data modification or execution of malicious code on the client system.
Statement
Red Hat ships Spring Integration as a bundled dependency in several middleware products. A flaw was found in Spring Integration's FTP, SFTP, and SMB inbound file synchronization adapters where server-supplied filenames are written to the local filesystem without path canonicalization, allowing a malicious or compromised remote server to write arbitrary files outside the configured local directory. Products shipping spring-integration-file, spring-integration-sftp, or spring-integration-ftp modules are directly exposed. Products bundling only spring-integration-core may not have the vulnerable code path but are included pending detailed analysis.
Mitigation
Restrict network access so that applications using Spring Integration file synchronization (FTP, SFTP, SMB inbound adapters) can only connect to trusted, known servers. Use firewall rules or network policies to prevent connections to untrusted endpoints. Additionally, run the application with minimal filesystem permissions to limit the impact of any arbitrary file write.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 7.1 | N/A | 7.1 |
| Attack Vector | Network | N/A | Network |
| Attack Complexity | High | N/A | High |
| Privileges Required | Low | N/A | Low |
| User Interaction | Required | N/A | Required |
| Scope | Changed | N/A | Changed |
| Confidentiality | Low | N/A | Low |
| Integrity Impact | High | N/A | High |
| Availability Impact | Low | N/A | Low |
Vector
Red Hat: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L
cve.org: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L
Understanding the Weakness (CWE)
Integrity,Confidentiality,Availability
Technical Impact: Execute Unauthorized Code or Commands
The attacker may be able to create or overwrite critical files that are used to execute code, such as programs or libraries.
Integrity
Technical Impact: Modify Files or Directories
The attacker may be able to overwrite or create critical files, such as programs, libraries, or important data. If the targeted file is used for a security mechanism, then the attacker may be able to bypass that mechanism. For example, appending a new account at the end of a password file may allow an attacker to bypass authentication.
Confidentiality
Technical Impact: Read Files or Directories
The attacker may be able read the contents of unexpected files and expose sensitive data. If the targeted file is used for a security mechanism, then the attacker may be able to bypass that mechanism. For example, by reading a password file, the attacker could conduct brute force password guessing attacks in order to break into an account on the system.
Availability
Technical Impact: DoS: Crash, Exit, or Restart
The attacker may be able to overwrite, delete, or corrupt unexpected critical files such as programs, libraries, or important data. This may prevent the product from working at all and in the case of protection mechanisms such as authentication, it has the potential to lock out product users.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.