← back
CVE-2026-2818highCWE-22CWE-23

Zip Slip Path Traversal in Snapshot Archive Extraction (Windows-Specific)

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.2epss 0.3%
exploitation probability
0.3%top 81% of all CVEs
observed exploitation
nono source reports it
A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N