CVE-2026-15704: Critical Auth Bypass in Eclipse BaSyx Go Components
ID: 50319b0d-6536-5fee-8f92-81a45e1c94ed
STIX ID: report--50319b0d-6536-5fee-8f92-81a45e1c94ed
Feed Name: CosmicBytez Labs
A critical authorization-bypass (CVE-2026-15704, CVSS 9.8) in Eclipse BaSyx Go Components (<= 1.0.0) allows unauthenticated attackers to bypass ABAC policies by appending a trailing slash; the ABAC middleware evaluates the slash-suffixed path while Chi's StripSlashes alters routing, resulting in a fail-open condition. The report details the root cause, attack vector, impacts to Industry 4.0/IIoT AAS deployments, detection indicators, and mitigations including patching, path normalization, deny-by-default policy, and WAF rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
