SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-59292

LOW · CVSS 3.2 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The PropertiesPersistingMetadataStore in affected versions of Spring Integration improperly sets world-readable permissions on the metadata store file located at ${java.io.tmpdir}/spring-integration/metadata-store.properties. This vulnerability could lead to unauthorized access to sensitive metadata, potentially exposing application state information to malicious actors. Organizations using the specified versions of Spring Integration should prioritize remediation to mitigate the risk of data exposure.

CVE
CVE-2026-59292
Severity
LOW
CVSS
3.2
EPSS
0.14%
Java

Original NVD Description

PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStore, persists its state to ${java.io.tmpdir}/spring-integration/metadata-store.properties with world-readable permissions. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier

Related CVEs

Other vulnerabilities affecting the same vendor(s)