CVE-2026-47894: Spring Cloud Config Server Native Environment Repository Exposure
Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the configured repository path. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14 and earlier
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
Deployments using the Spring Cloud Config Server native environment repository are affected if they run Spring Cloud Config 5.0.0 through 5.0.4, 4.3.0 through 4.3.4, 4.0.0 through 4.2.8, or 3.1.14 and earlier.
What level of access does an attacker need?
The CVSS vector indicates that exploitation is network-accessible but requires high privileges. No user interaction is required.
What is the expected security impact?
The reported impact is limited to confidentiality: configuration files outside the configured repository path may be exposed. The supplied CVSS vector does not indicate integrity or availability impact.