CVE-2026-2818HIGH 8.2EPSS p19.4%
CVE-2026-2818CVE-2026-2818
Description
A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only.
Scoring
| CVSS 3.1 | 8.2 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N |
| EPSS | 0.27% probability of exploitation · percentile 19.4% · 2026-08-03T12:00:16Z |
| Published | 2026-02-20 |
| Last modified | 2026-07-15 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Relative Path Traversalcwe-23 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.