Path traversal in Spring Integration - CVE-2026-40987
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote user to write arbitrary files on the client filesystem with attacker-controlled content.
The vulnerability exists due to improper pathname limitation in remote-file synchronizer when synchronizing files from a malicious or compromised FTP, SFTP, or SMB server. A remote user can supply a crafted filename to write arbitrary files on the client filesystem with attacker-controlled content.
User interaction is required to initiate synchronization with the malicious or compromised server.