---
cve: "CVE-2026-2818"
severity: "HIGH"
cvss: 8.2
epss: "27%"
vendor: "VMware"
kev: false
exploited: false
published: "2026-02-20 17:25:57"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T11:11:57+02:00"
---

# CVE-2026-2818

> 8.2 HIGH

## Beschreibung

A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Erforderlich | good |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Keine | good |

## Referenzen

- <https://www.herodevs.com/vulnerability-directory/cve-2026-2818>
- <https://access.redhat.com/security/cve/CVE-2026-2818>
- <https://bugzilla.redhat.com/show_bug.cgi?id=2441384>
- <https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2818.json>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-2818) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
