UBUNTU-CVE-2026-7411

Source
https://ubuntu.com/security/CVE-2026-7411
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-7411.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-7411
Upstream
  • CVE-2026-7411
Published
2026-05-05T16:16:00Z
Modified
2026-05-14T14:56:45.892027Z
Severity
  • 10.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequate path normalization in the Submodel HTTP API allows an unauthenticated remote attacker to perform a path traversal attack. By supplying a maliciously crafted fileName parameter during a file upload operation, an attacker can bypass intended storage boundaries and write arbitrary files to any location on the host filesystem accessible by the Java process. This can lead to Remote Code Execution (RCE) and complete system compromise.

References

Affected packages

Ubuntu:16.04:LTS / eclipse

Package

Name
eclipse
Purl
pkg:deb/ubuntu/eclipse@3.8.1-8?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.8.1-8

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "eclipse",
            "binary_version": "3.8.1-8"
        },
        {
            "binary_name": "eclipse-jdt",
            "binary_version": "3.8.1-8"
        },
        {
            "binary_name": "eclipse-pde",
            "binary_version": "3.8.1-8"
        },
        {
            "binary_name": "eclipse-platform",
            "binary_version": "3.8.1-8"
        },
        {
            "binary_name": "eclipse-platform-data",
            "binary_version": "3.8.1-8"
        },
        {
            "binary_name": "eclipse-rcp",
            "binary_version": "3.8.1-8"
        },
        {
            "binary_name": "libequinox-osgi-java",
            "binary_version": "3.8.1-8"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-7411.json"

Ubuntu:18.04:LTS / eclipse

Package

Name
eclipse
Purl
pkg:deb/ubuntu/eclipse@3.8.1-11?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.8.1-10
3.8.1-11

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "eclipse",
            "binary_version": "3.8.1-11"
        },
        {
            "binary_name": "eclipse-jdt",
            "binary_version": "3.8.1-11"
        },
        {
            "binary_name": "eclipse-pde",
            "binary_version": "3.8.1-11"
        },
        {
            "binary_name": "eclipse-platform",
            "binary_version": "3.8.1-11"
        },
        {
            "binary_name": "eclipse-platform-data",
            "binary_version": "3.8.1-11"
        },
        {
            "binary_name": "eclipse-rcp",
            "binary_version": "3.8.1-11"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-7411.json"