CVE-2026-101322

Source
https://cve.org/CVERecord?id=CVE-2026-101322
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-101322.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-101322
Published
2026-10-01T16:00:50Z
Modified
2026-10-02T03:47:13Z
Severity
  • 8.3 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N CVSS Calculator
Summary
[none]
Details

In Eclipse BaSyx AAS Web UI versions v2-241220 through releases before v2-260924, the shared request handler attached the selected infrastructure's Authorization header to outgoing requests without checking the destination origin. In deployments using authentication, an attacker could induce a user to open a crafted Web UI link whose aas or path query parameter points to an attacker-controlled endpoint. The user's browser would then send the configured Basic Authentication credentials, Bearer token, or an available OAuth2 access token to that endpoint. The attacker could reuse the disclosed credential to access protected AAS services with the victim's privileges. The issue is fixed in v2-260924.

Database specific
{
    "cna_assigner":  "eclipse",
    "cwe_ids":  [
        "CWE-201"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/101xxx/CVE-2026-101322.json"
}
References

Affected packages

Git / github.com/eclipse-basyx/basyx-aas-web-ui

Affected ranges

Type
GIT
Repo
https://github.com/eclipse-basyx/basyx-aas-web-ui
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "v2-241220"
        },
        {
            "fixed":  "v2-260924"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

Other
v2-241220
v2-250305
v2-250417
v2-250618
v2-250821
v2-250916
v2-251001
v2-260122
v2-260505
v2-260526
v2-260707
v2-260721
v2-260801
v2-260910

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-101322.json"