CVE-2026-2818HIGH 8.2EPSS p15.8%
CVE-2026-2818CVE-2026-2818
Description
A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only.
Scoring
| CVSS 3.1 | 8.2 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N |
| EPSS | 0.25% probability of exploitation · percentile 15.8% · 2026-06-19T12:03:05Z |
| Published | 2026-02-20 |
| Last modified | 2026-04-15 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Relative Path Traversalcwe-23 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.