CVE-2026-47894
Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the configured repository path. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14 and earlier
- Published Aug 27, 2026
- CVSS 7.5 high
- 0.5% chance of exploitation in the next 30 days (EPSS)