Bug 2524602 (CVE-2026-47836)

Summary: CVE-2026-47836 org.springframework.cloud/spring-cloud-config-server: Spring Cloud Config Server: TOCTOU vulnerability in SVN base directory
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: rhel-process-autobot, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Spring Cloud Config Server. The base directory used by the server to clone SVN repositories is susceptible to a Time-of-Check Time-of-Use (TOCTOU) attack. A local attacker with high privileges could exploit this vulnerability by manipulating the directory between the security check and its subsequent use. This could lead to unauthorized modification of files or disclosure of sensitive information.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2537352    
Bug Blocks:    

Description OSIDB Bzimport 2026-08-26 18:46:58 UTC
The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks.
Spring Cloud Config 5.0.0 - 5.0.4
Spring Cloud Config 4.3.0 - 4.3.4
Spring Cloud Config 4.0.0 - 4.2.8
Spring Cloud Config 3.1.14 and earlier