VYPR
High severity7.1NVD Advisory· Published Jun 11, 2026· Updated Sep 4, 2026

CVE-2026-40987

CVE-2026-40987

Description

A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled content.

Affected versions: Spring Integration 7.0.0 through 7.0.4; 6.5.0 through 6.5.8; 6.4.0 through 6.4.11; 6.3.0 through 6.3.14; 5.5.0 through 5.5.20.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.springframework.integration:spring-integration-fileMaven
>= 7.0.0, < 7.0.57.0.5
org.springframework.integration:spring-integration-fileMaven
>= 6.5.0, < 6.5.96.5.9
org.springframework.integration:spring-integration-fileMaven
>= 6.4.0, <= 6.4.11
org.springframework.integration:spring-integration-fileMaven
>= 6.3.0, <= 6.3.14
org.springframework.integration:spring-integration-fileMaven
<= 5.5.20

Affected products

1

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.