PULSE
EN VIVO54señales / 24h
FEED
ransomsection9 reclama a ******.net.br · BR · Financial Servicesransomsection9 reclama a ******.com.br · BR · Otherransomsection9 reclama a ********.com.br · BR · Not Foundransomglobal secret group reclama a Prism Telecom · FI · Technologyransomglobal secret group reclama a Cipher Dynamics · IN · Technologyransomglobal secret group reclama a Stratos Network · AE · Technologyransomglobal secret group reclama a OmniLink AG · DE · Technologyransomglobal secret group reclama a Vertex Systems · US · Technologyransomglobal secret group reclama a Nexon Corp. · KR · Technologyransomglobal secret group reclama a Farmers Mutual Fire Insurance · US · Financial Servicesransomglobal secret group reclama a West Sixth Law · US · Professional Servicesransomglobal secret group reclama a Baker Business & Tax Solutions · US · Professional Servicesransomglobal secret group reclama a Carpets Direct · US · Retail & E-Commerceransomglobal secret group reclama a AnyWeather · US · Technologyransomsection9 reclama a ******.net.br · BR · Financial Servicesransomsection9 reclama a ******.com.br · BR · Otherransomsection9 reclama a ********.com.br · BR · Not Foundransomglobal secret group reclama a Prism Telecom · FI · Technologyransomglobal secret group reclama a Cipher Dynamics · IN · Technologyransomglobal secret group reclama a Stratos Network · AE · Technologyransomglobal secret group reclama a OmniLink AG · DE · Technologyransomglobal secret group reclama a Vertex Systems · US · Technologyransomglobal secret group reclama a Nexon Corp. · KR · Technologyransomglobal secret group reclama a Farmers Mutual Fire Insurance · US · Financial Servicesransomglobal secret group reclama a West Sixth Law · US · Professional Servicesransomglobal secret group reclama a Baker Business & Tax Solutions · US · Professional Servicesransomglobal secret group reclama a Carpets Direct · US · Retail & E-Commerceransomglobal secret group reclama a AnyWeather · US · Technology
← Todos los CVEs
CVE Watch24 jul 2026

CVE-2026-40973

A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.se

CVSS

7.0

Alto

EPSS

0.1%

p3

KEV

Exploit Today

1

0-100

Publicado: 28 abr 2026 · Última mod.: 24 jul 2026 · CWE-377

EPSS · 30d
0.1%EPSS · 30 días0.1%
2026-06-302026-07-25
Descripción técnica

A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.session.persistent` is set to `true` and the attack persists across application restarts, this may allow the attacker to read session information and hijack authenticated users or deploy a gadget chain and execute code as the application's user. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); predictable temp directory / `ApplicationTemp` ownership verification. Versions that are no longer supported are also affected per vendor advisory.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-448787.2 ALT
33.8%
10A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated remote attacker to access the device's filesystem. Successful exploitation of this vulnerability could allow an attacker to access sensitive files and tamper with or delete system data.3d
CVE-2026-62294
1.1%
0Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to a predictable temporary path and followed symlinks, creating a time-of-check to time-of-use race that allowed a local unprivileged attacker on the same machine to pre-plant a symlink and cause Flameshot to write PNG data through it, overwriting any file the victim user could write. This issue is fixed in version 14.0.0.11d
CVE-2026-464066.1 MED
1.7%
1Claude Code is an agentic coding tool. From 2.1.59 until 2.1.128, the Claude Code /copy command wrote responses to a hardcoded, predictable path (/tmp/claude/response.md) without UID isolation, randomness, or symlink protection. The file was created world-readable (0644) in a world-traversable directory (0755), allowing any local user to read a privileged user's Claude response, which could contain secrets or credentials. Additionally, because the path was static and predictable, a local attacker could pre-create the directory and plant a symlink at the expected file path, causing the privileged process to follow the symlink and overwrite an attacker-chosen file with the response text. Exploiting this required a local unprivileged user on the same system and a privileged user to run the /copy command. This vulnerability is fixed in 2.1.128.26d
CVE-2026-419914.7 MED
2.0%
1GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks. A local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite. This issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d426925d
CVE-2026-410015.3 MED
0.8%
0Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A local attacker on the same host can pre-create this predictable directory or place a symlink before the application starts. Affected versions: Spring Boot 4.0.0 through 4.0.6; 3.5.0 through 3.5.14; 3.4.0 through 3.4.16; 3.3.0 through 3.3.19; 2.7.0 through 2.7.33.3d
CVE-2026-453846.1 MED
2.6%
1bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.12, there is an arbitrary file overwrite vulnerability via symlink attack on predictable temp files during archive update. This issue has been patched in version 4.0.12.3d