CVE-2026-41001
published 2026-06-11CVE-2026-41001: Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is…
PriorityP426medium5.3CVSS 3.1
AVLACLPRLUINSUCLILAL
EPSS
0.09%
0.8th percentile
Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A local attacker on the same host can pre-create this predictable directory or place a symlink before the application starts.
Affected versions:
Spring Boot 4.0.0 through 4.0.6; 3.5.0 through 3.5.14; 3.4.0 through 3.4.16; 3.3.0 through 3.3.19; 2.7.0 through 2.7.33.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| log4j_2 | log4j | — | — |
| spring | spring_boot | >= 2.7.0 < 2.7.34 | 2.7.34 |
| spring | spring_boot | >= 3.3.0 < 3.3.20 | 3.3.20 |
| spring | spring_boot | >= 3.4.0 < 3.4.17 | 3.4.17 |
| spring | spring_boot | >= 3.5.0 < 3.5.14.1 | 3.5.14.1 |
| spring | spring_boot | >= 4.0.0 < 4.0.6.1 | 4.0.6.1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
spring-boot: Spring Boot: Local attacker can manipulate data directory due to predictable path
vendor_redhat·2026-06-11·CVSS 5.3
CVE-2026-41001 [MEDIUM] CWE-1188 spring-boot: Spring Boot: Local attacker can manipulate data directory due to predictable path
spring-boot: Spring Boot: Local attacker can manipulate data directory due to predictable path
Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A local attacker on the same host can pre-create this predictable directory or place a symlink before the application starts.
Affected versions:
Spring Boot 4.0.0 through 4.0.6; 3.5.0 through 3.5.14; 3.4.0 through 3.4.16; 3.3.0 through 3.3.19; 2.7.0 through 2.7.33.
A flaw was found in Spring Boot. The ArtemisEmbeddedConfigurationFactory component uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A local attacker on the same host can exploit this by pre-creati
GHSA
Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured.
ghsa_unreviewed·2026-06-11
CVE-2026-41001 [MEDIUM] CWE-377 Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured.
Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A local attacker on the same host can pre-create this predictable directory or place a symlink before the application starts.
Affected versions:
Spring Boot 4.0.0 through 4.0.6; 3.5.0 through 3.5.14; 3.4.0 through 3.4.16; 3.3.0 through 3.3.19; 2.7.0 through 2.7.33.
No detection rules found.
No public exploits indexed.
2026-06-11
Published