logo

CVE-2026-57898: Eclipse BaSyx Unauthenticated File Write in IIoT SDK (CVSS 9.0)

ID: 8d934620-c5c0-509f-ae5b-106c5b3604de

STIX ID: report--8d934620-c5c0-509f-ae5b-106c5b3604de

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-07-15

Date Updated: 2026-07-15

...
...

A critical unauthenticated arbitrary file write vulnerability (CVE-2026-57898, CVSS 9.0) in the Eclipse BaSyx Java Server SDK thumbnail upload API allows attackers to supply a client-controlled fileName (including path traversal) and write arbitrary files to hosts using the MongoDB backend; this can lead to remote code execution, OT network pivoting, data tampering, and supply-chain disruption. The report identifies affected versions (2.0.0-milestone-05 through milestone-12), provides an exploitation scenario and detection indicators, and recommends immediate actions including patching to a fixed release, restricting API access, adding authentication, and scanning for compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.