Use of insecure directory in Spring Data Geode snapshot import extracts archives into predictable, permissive directories under the system temp location. On shared hosts, a local user with basic privileges can access another user’s extracted snapshot contents, leading to unintended exposure of cache data.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 19 Feb 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Use of insecure directory in Spring Data Geode snapshot import extracts archives into predictable, permissive directories under the system temp location. On shared hosts, a local user with basic privileges can access another user’s extracted snapshot contents, leading to unintended exposure of cache data. | |
| Title | Spring Data Geode Insecure Temporary Directory Usage | |
| Weaknesses | CWE-378 CWE-379 CWE-538 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: HeroDevs
Published:
Updated: 2026-02-19T17:18:09.839Z
Reserved: 2026-02-19T17:07:39.475Z
Link: CVE-2026-2817
No data.
Status : Received
Published: 2026-02-19T18:25:00.983
Modified: 2026-02-19T18:25:00.983
Link: CVE-2026-2817
No data.
OpenCVE Enrichment
No data.