CVE 10 CRITICAL

CVE-2026-7411_CVE-2026-7411

10 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Description

In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequate path normalization in the Submodel HTTP API allows an unauthenticated remote attacker to perform a path traversal attack. By supplying a maliciously crafted fileName parameter during a file upload operation, an attacker can bypass intended storage boundaries and write arbitrary files to any location on the host filesystem accessible by the Java process. This can lead to Remote Code Execution (RCE) and complete system compromise.

AI Analysis

Path traversal vulnerability allowing remote code execution in Eclipse BaSyx Java Server SDK

Basic Information

ID CVE-2026-7411
Source eclipse
Published May 5, 2026 at 14:07

Affected Product

Vendor Eclipse Foundation
Product Eclipse BaSyx
Affected Versions Eclipse Foundation Eclipse BaSyx 0

CWE Classification

AI Assessment

AI Score 10 / 10
AI Severity Critical
Vendor Eclipse Foundation
Product Eclipse BaSyx Java Server SDK
Version prior to 2.0.0-milestone-10

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.