← All reports

The Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10 are vulnerable to path traversal and SSRF attacks, allowing remote code execution and unauthorized access to internal systems.

CybersecurityTechnologyConflictEclipse BasyxMay 17, 2026score 0.172 posts · 0 replies across 1 instances
The thread discusses two critical security vulnerabilities in the Eclipse BaSyx Java Server SDK, CVE-2026-7411 and CVE-2026-7412, which allow remote code execution and SSRF attacks. These vulnerabilities pose significant risks to systems using the SDK, emphasizing the need for immediate updates.

Claims

The Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10 are vulnerable to path traversal and SSRF attacks, allowing remote code execution and unauthorized access to internal systems.
Parent: CybersecurityEntity: Eclipse BaSyx Java Server SDKImpact: negativeDate: May 17, 2026Target: The security of the Eclipse BaSyx Java Server SDK

Source posts

@[email protected]
Vulnerability Cve-2026-7412 Eclipse BaSyx Java Server SDK 버전 2.0.0-milestone-10 이전에서 Operation Delegation 기능이 위임 요청의 대상 URI를 검증하지 않아 인증되지 않은 원격 공격자가 임의의 내부 또는 외부 대상에 대해 블라인드 HTTP POST 요청을 실행할 수 있는 SSRF 취약점(CVE-2026-7412)이 발견되었습니다. 이 취약점은 네트워크 분할을 우회하고 내부 IT/OT 인프라 또는 클라우드 메타데이터 서비스(IMDS)를 공격하는 데 악용될 수 있습니다. CVSS 점수는 8.6으로 높은 심각도를 가집니다. https://db.gcve.eu/vuln/cve-2026-7412 #security #ssrf #eclipse #vulnerability #sdk
0 boosts · 0 favs · 0 replies · May 17, 2026
#security#ssrf#eclipse#vulnerability#sdk
@[email protected]
Vulnerability Cve-2026-7411 Eclipse BaSyx Java Server SDK 버전 2.0.0-milestone-10 이전에서 Submodel HTTP API의 부적절한 경로 정규화 취약점(CVE-2026-7411)이 발견되었습니다. 인증되지 않은 원격 공격자가 악의적으로 조작된 fileName 파라미터를 이용해 경로 탐색 공격을 수행, 임의의 파일을 서버 파일 시스템에 쓸 수 있어 원격 코드 실행(RCE) 및 시스템 완전 장악이 가능합니다. 이 취약점은 네트워크 공격 벡터, 낮은 공격 복잡도, 권한 요구 없음으로 CVSS 10점의 치명적 위험도를 가집니다. 해당 SDK를 사용하는 AI 인프라 및 서비스 개발자는 즉시 버전 업데이트 및 보안 패치를 적용해야 합니다. https://db.gcve.eu/vuln/cve-2026-7411 #security #cve #pathtraversal #rce #eclipse
0 boosts · 0 favs · 0 replies · May 17, 2026
#security#cve#pathtraversal#rce#eclipse