CVE-2026-57898
Last modified
CVE-2026-57898 is a critical-severity vulnerability rated 9/10 on the CVSS scale. In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauthenticated arbitrary file write through the AAS thumbnail API. The AAS thumbnail upload path accepted a client-controlled fileName request parameter and passed it through repository file handling as both a repository key and, during thumbnail retrieval, a local filesystem path. With the MongoDB file repository, the supplied filename was treated as an opaque GridFS key and was not normalized or restricted as a filesystem path. EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauthenticated arbitrary file write through the AAS thumbnail API. The AAS thumbnail upload path accepted a client-controlled fileName request parameter and passed it through repository file handling as both a repository key and, during thumbnail retrieval, a local filesystem path. With the MongoDB file repository, the supplied filename was treated as an opaque GridFS key and was not normalized or restricted as a filesystem path. A remote attacker could upload thumbnail content using an absolute or traversal-style filename, then trigger thumbnail retrieval so that the uploaded bytes were written to the attacker-chosen path on the server filesystem. This could allow writing files anywhere the Java process has permission to write and may lead to remote code execution. The default InMemory backend is not affected by this specific path because it normalizes and restricts file paths to its temporary directory. The issue is fixed in Eclipse BaSyx Java Server SDK 2.0.0-milestone-13.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Eclipse Foundation | Eclipse BaSyx - Java Server SDK | >= 2.0.0-milestone-05, < 2.0.0-milestone-13 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-57898?
How severe is CVE-2026-57898?
How do I fix CVE-2026-57898?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5788An Improper Access Control in Ivanti EPMM before versions 12…9.8
- CVE-2026-57880An unauthenticated stack-based buffer overflow vulnerability…9.8
- CVE-2026-57881An unauthenticated stack-based buffer overflow vulnerability…9.8
- CVE-2026-5789Vulnerability related to an unquoted search path in CivetWeb…7.8
- CVE-2026-57895Incorrect default permissions issue exists in Pupsman versio…8.5
- CVE-2026-57896An out-of-bounds read vulnerability in the Productivity Suit…6.9
- CVE-2026-5790Stored Cross-Site Scripting (XSS) in Stel Order v3.25.1 and …5.1
- CVE-2026-5791Cross-Site request forgery (CSRF) vulnerability in DivvyDriv…6.5
- CVE-2026-57912Johnson & Johnson Campus Recruiting before 2025-10-31 allows…7.5
- CVE-2026-57913Johnson & Johnson Audit Tracking Management System (ATMS) be…7.5
- CVE-2026-57914By sending a deeply nested ASN1 structure to a Apache Kerby …6.5
- CVE-2026-57915It is possible to bypass the Kerberos pre-authentication che…7.3
Are you affected by CVE-2026-57898?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
