Medium severity5.3NVD Advisory· Published Jun 11, 2026· Updated Sep 4, 2026
CVE-2026-41001
CVE-2026-41001
Description
Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A local attacker on the same host can pre-create this predictable directory or place a symlink before the application starts.
Affected versions: Spring Boot 4.0.0 through 4.0.6; 3.5.0 through 3.5.14; 3.4.0 through 3.4.16; 3.3.0 through 3.3.19; 2.7.0 through 2.7.33.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.springframework.boot:spring-boot-autoconfigureMaven | >= 4.0.0, < 4.0.7 | 4.0.7 |
org.springframework.boot:spring-boot-autoconfigureMaven | >= 3.5.0, < 3.5.15 | 3.5.15 |
org.springframework.boot:spring-boot-autoconfigureMaven | >= 3.4.0, <= 3.4.16 | — |
org.springframework.boot:spring-boot-autoconfigureMaven | >= 3.3.0, <= 3.3.19 | — |
org.springframework.boot:spring-boot-autoconfigureMaven | >= 2.7.0, <= 2.7.33 | — |
Affected products
8- Range: >=2.7.0,<=2.7.33 || >=3.3.0,<=3.3.19 || >=3.4.0,<=3.4.16 || >=3.5.0,<=3.5.14 || >=4.0.0,<=4.0.6
- Range: 4.0.0 through 4.0.6; 3.5.0 through 3.5.14; 3.4.0 through 3.4.16; 3.3.0 through 3.3.19; 2.7.0 through 2.7.33
- osv-coords6 versionspkg:apk/chainguard/apache-nifi-registry-2.11pkg:apk/chainguard/camunda-zeebe-8.6pkg:apk/chainguard/keycloak-config-clipkg:apk/chainguard/keycloak-config-cli-iamguarded-compatpkg:apk/wolfi/keycloak-config-clipkg:apk/wolfi/keycloak-config-cli-iamguarded-compat
< 2.11.0-r3+ 5 more
- (no CPE)range: < 2.11.0-r3
- (no CPE)range: < 8.6.39-r11
- (no CPE)range: < 6.5.1-r15
- (no CPE)range: < 6.5.1-r15
- (no CPE)range: < 6.5.1-r15
- (no CPE)range: < 6.5.1-r15
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-ggg2-9786-hwc8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-41001ghsaADVISORY
- spring.io/security/cve-2026-41001nvdVendor AdvisoryWEB
- github.com/spring-projects/spring-boot/commit/4218bd76e934e5cf9e3fd3997c67b8a6b0d0c111ghsaWEB
News mentions
0No linked articles in our index yet.