WeSearch

Vulnerability Cve-2026-7411

·26 min read · 0 reactions · 0 comments · 8 views
#cybersecurity#software vulnerability#path traversal#remote code execution#cve
Vulnerability Cve-2026-7411
⚡ TL;DR · AI summary

CVE-2026-7411 is a critical vulnerability in Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10. It stems from inadequate path normalization in the Submodel HTTP API, enabling unauthenticated remote attackers to perform path traversal attacks. This can result in arbitrary file writes, remote code execution, and full system compromise.

Key facts
Original article
Gcve
Read full at Gcve →
Opening excerpt (first ~120 words) tap to expand

Action not permitted Modal body text goes here. Close Modal Title Modal Body Source (Optional) Cancel Confirm CVE-2026-7411 (GCVE-0-2026-7411) Vulnerability from cvelistv5 – Published: 2026-05-05 14:07 – Updated: 2026-05-06 15:25 VLAI? EPSS SummaryIn Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequate path normalization in the Submodel HTTP API allows an unauthenticated remote attacker to perform a path traversal attack. By supplying a maliciously crafted fileName parameter during a file upload operation, an attacker can bypass intended storage boundaries and write arbitrary files to any location on the host filesystem accessible by the Java process. This can lead to Remote Code Execution (RCE) and complete system compromise.

Excerpt limited to ~120 words for fair-use compliance. The full article is at Gcve.

Anonymous · no account needed
Share 𝕏 Facebook Reddit LinkedIn Threads WhatsApp Bluesky Mastodon Email

Discussion

0 comments

More from Gcve