cbcvebase.
CVE-2026-47852
published 2026-08-27

CVE-2026-47852: A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spring AI 2.0.0 Spring AI 1.1.0 -…

PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.20%
10.2th percentile
A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9

Affected

6 ranges
VendorProductVersion rangeFixed in
springspring_ai
springspring_ai1.0.0 – 1.0.9
springspring_ai1.1.0 – 1.1.8
vmwarespring_ai>= 1.0.0 < 1.0.101.0.10
vmwarespring_ai>= 1.1.0 < 1.1.91.1.9
vmwarespring_ai>= 2.0.0 < 2.0.0.12.0.0.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.