CVE-2026-40987: Remote-file synchronizer in Spring Integration writes server-supplied filename under localDirectory without canonicalization
A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled content.
Affected versions: Spring Integration 7.0.0 through 7.0.4; 6.5.0 through 6.5.8; 6.4.0 through 6.4.11; 6.3.0 through 6.3.14; 5.5.0 through 5.5.20.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40987?
CVE-2026-40987 has a high severity rating of 7.1.
How do I fix CVE-2026-40987?
To fix CVE-2026-40987, upgrade to the latest version of Spring Integration that addresses this vulnerability.
What types of servers are affected by CVE-2026-40987?
CVE-2026-40987 is affected by malicious or compromised FTP, SFTP, or SMB servers.
What is the potential impact of CVE-2026-40987?
CVE-2026-40987 allows attackers to write arbitrary files to the client filesystem, potentially leading to data compromise.
Which versions of Spring Integration are vulnerable to CVE-2026-40987?
Spring Integration versions 7.0.0 through 7.0.4, 6.5.0 through 6.5.8, 6.4.0 through 6.4.11, and 6.3.0 through 6.3.10 are vulnerable to CVE-2026-40987.