CVE-2026-57898
Eclipse Foundation Eclipse BaSyx - Java Server SDK
In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauthenticated arbitrary file write through the AAS thumbnail API. The AAS thumbnail upload path accepted a client-controlled fileName request parameter and passed it through repository file handling as both a repository key and, during thumbnail retrieval, a local filesystem path. With the MongoDB file repository, the supplied filename was treated as an opaque GridFS key and was not normalized or restricted as a filesystem path. A remote attacker c...
- CVSS
- 9
- EPSS
- 0.45% 36.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.14