CVE-2026-40987 is a high-severity path traversal vulnerability in Spring Integration's remote file synchronization logic, specifically the InboundFileSynchronizer used by the FTP, SFTP, and SMB inbound channel adapters. The flaw is caused by missing filename canonicalization when processing server-supplied filenames before writing them beneath the configured local download directory. Because the synchronizer trusts remote filenames without properly normalizing and constraining them to the intended directory, a malicious or compromised remote server can supply traversal sequences and cause files with attacker-controlled content to be written to arbitrary locations on the client filesystem outside the configured localDirectory. Affected versions are Spring Integration 7.0.0 through 7.0.4, 6.5.0 through 6.5.8, 6.4.0 through 6.4.11, 6.3.0 through 6.3.14, and 5.5.0 through 5.5.20.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a minimal Java/Maven proof-of-concept reproducer for CVE-2026-40987, a Spring Integration remote-file path traversal vulnerability. It is not a weaponized exploit or framework module; instead it contains two JUnit tests that demonstrate attacker-controlled file write outside a configured local synchronization directory. Repository structure: README.md documents the issue, affected components, vulnerable code path, and test execution. pom.xml defines a Maven test project using Java 17 with spring-integration-file and spring-integration-ftp dependencies plus JUnit/AssertJ. The only substantive code is under src/test/java in two Java test classes. mvnw, mvnw.cmd, and .mvn/wrapper/* are standard Maven wrapper files. Main exploit capabilities: The exploit abuses Spring Integration's use of server-supplied remote filenames when constructing local destination paths. By returning filenames containing '../', a malicious remote server can cause synchronized content to be written outside the intended localDirectory. The provided result is arbitrary file write relative to the client filesystem location of the configured download directory. Code details: SpringIntegrationRemoteFilePathTraversalTest directly exercises AbstractInboundFileSynchronizer with a mock Session implementation that returns '../escaped-by-spring-integration.txt' from list(), then writes controlled bytes during read(). This proves the core vulnerable logic independent of a real protocol server. SpringIntegrationFtpPathTraversalTest is the more realistic networked reproducer: it spins up an in-process malicious FTP server on 127.0.0.1 using ServerSocket, advertises a LIST entry named '../escaped-by-ftp-list.txt', and serves file content over passive-mode data connections. The test then configures DefaultFtpSessionFactory and FtpInboundFileSynchronizer to connect to that server and verifies that the file is written outside the downloads directory and that the client issued 'RETR incoming/../escaped-by-ftp-list.txt'. Attack surface: network and file-system. The vulnerable scenario requires a client connecting to a malicious or compromised FTP/SFTP/SMB-like remote file server through Spring Integration inbound synchronization. This repository specifically exercises FTP and the generic remote-file synchronizer abstraction. Overall purpose: to provide a reliable, minimal reproducer for validating the vulnerability and demonstrating impact, not to deliver post-exploitation payloads or persistence.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A path traversal vulnerability in the Spring Integration synchronizer module that allows arbitrary local file writes outside configured directories via compromised file servers.
A path traversal/arbitrary file write vulnerability in Spring Integration's InboundFileSynchronizer caused by missing filename canonicalization, allowing malicious or compromised FTP, SFTP, or SMB servers to write attacker-controlled files outside the intended local download directory.
A path traversal/arbitrary file write vulnerability in Spring Integration's remote-file synchronizer where a malicious or compromised FTP, SFTP, or SMB server can cause files to be written outside the configured local directory with attacker-controlled content.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.