CVE-2026-2818HIGH 8.2EPSS p15.8%

CVE-2026-2818CVE-2026-2818

Description

A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only.

Scoring

CVSS 3.18.2 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N
EPSS0.25% probability of exploitation · percentile 15.8% · 2026-06-19T12:03:05Z
Published2026-02-20
Last modified2026-04-15

Underlying weaknesses· 1

CWE-23

References

  1. https://www.herodevs.com/vulnerability-directory/cve-2026-2818

1

TypeTargetConfidenceTier
WeaknessRelative Path Traversalcwe-230%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-0851
CVE
CVE-2026-3087
CVE
CVE-2026-10621
CVE
CVE-2025-0377
CVE
CVE-2025-66945
CVE
CVE-2025-67030
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.