CVE-2026-41002 is a time-of-check-time-of-use race condition in Spring Cloud Config Server's handling of the spring.cloud.config.server.git.basedir directory used to clone Git repositories. A locally privileged attacker may manipulate the directory during the gap between its validation and subsequent use, potentially redirecting repository-cloning activity to an attacker-controlled filesystem location. This can expose or alter configuration data distributed by the Config Server to downstream microservices.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
spring.cloud.config.server.git.basedir so unauthorized users and processes cannot manipulate it. Upgrade to a supported fixed release as soon as possible.Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity TOCTOU race condition in Spring Cloud Config Server affecting the base directory used to clone Git repositories, allowing file manipulation during the cloning process.
A TOCTOU vulnerability affecting Spring Cloud Config Server.
A high-severity TOCTOU race condition in Spring Cloud Config Server's Git repository cloning/base directory handling that can let a locally privileged attacker manipulate the configuration storage directory and expose or alter sensitive configuration data.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.