CVE-2026-47894

Source
https://cve.org/CVERecord?id=CVE-2026-47894
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47894.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-47894
Published
2026-08-27T05:20:32Z
Modified
2026-09-03T03:47:04Z
Severity
  • 4.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Spring Cloud Config Server Native Environment Repository Exposure
Details

Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the configured repository path. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14 and earlier

Database specific
{
    "cna_assigner": "vmware",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47894.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "5.0.0"
                },
                {
                    "last_affected": "5.0.4"
                },
                {
                    "introduced": "4.3.0"
                },
                {
                    "last_affected": "4.3.4"
                },
                {
                    "introduced": "4.0.0"
                },
                {
                    "last_affected": "4.2.8"
                },
                {
                    "last_affected": "3.1.14"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/spring-cloud/spring-cloud-config

Affected ranges

Type
GIT
Repo
https://github.com/spring-cloud/spring-cloud-config
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:vmware:spring_cloud_config:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "5.0.0"
        },
        {
            "fixed": "5.0.5"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

v5.*
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47894.json"