Intel

AIKIDO-2026-386653

spring-boot-autoconfigure is vulnerable to Insecure Temporary File

Insecure Temporary FileCVE-2026-41001 Published Jun 15, 2026

53

Medium Risk

This Affects:

JAVAspring-boot-autoconfigure
0.0.1 - 3.5.14
Fixed in 3.5.15
4.0.0 - 4.0.6
Fixed in 4.0.7
Are you affected? Scan for Free

TL;DR

Spring Boot's Artemis auto-configuration uses a predictable, static directory for embedded Artemis broker data when no custom data directory is configured. A local attacker with access to the same host can pre-create the directory or replace it with a symbolic link before application startup, potentially enabling unauthorized access to message queue data, message tampering, or further exploitation through malicious journal contents.

Who does this affect?

You are affected if using a vulnerable version.

Background info

spring-boot-autoconfigure is vulnerable to Insecure Temporary File in versions 0.0.1 - 3.5.14 and 4.0.0 - 4.0.6.

How to fix this

Upgrade the org.springframework.boot:spring-boot-autoconfigure library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform