CVE-2026-59284

Updated on 27 Aug 2026

Severity

7.0 High severity

Details

CVSS score
7.0
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:L

Overview

About vulnerability

There is no allow list for property keys when Spring Cloud Commons writable /actuator/env is enabled.

Details

Affected product:
Apache Log4j , Spring , camel
Affected packages:
Spring Cloud @ 3.1.9 (+1175 more)