SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-59280

MEDIUM · CVSS 4.3 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Applications utilizing the Spring Framework's FreeMarker integration are susceptible to a path traversal vulnerability when untrusted input is used to derive view names, particularly if FreeMarker is set to resolve templates via SpringTemplateLoader. This flaw could allow attackers to access unintended files on the server, potentially leading to data exposure or system compromise. Organizations employing affected versions of the Spring Framework, especially those handling user-generated input for view rendering, should prioritize remediation efforts to mitigate this risk.

CVE
CVE-2026-59280
Severity
MEDIUM
CVSS
4.3
EPSS
0.24%

Original NVD Description

Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a controller returns a view name derived from untrusted input and FreeMarker is configured to resolve templates through SpringTemplateLoader. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier

Related CVEs

Other vulnerabilities affecting the same vendor(s)