CVE-2026-7411Disclosure

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequate path normalization in the Submodel HTTP API allows an unauthenticated remote attacker to perform a path traversal attack. By supplying a maliciously crafted fileName parameter during a file upload operation, an attacker can bypass intended storage boundaries and write arbitrary files to any location on the host filesystem accessible by the Java process. This can lead to Remote Code Execution (RCE) and complete system compromise.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-05-14); latest day: 1
  • 7 total mentions across 4 days

Deep dive

Activity timeline7 mentions / 4d
01234Mentions · 2026-05-06: 1Mentions · 2026-05-09: 1Mentions · 2026-05-14: 4Mentions · 2026-05-17: 1Patch / Workaround · 2026-05-06: 1Patch / Workaround · 2026-05-17: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-09: 1Technical Details · 2026-05-14: 3Technical Details · 2026-05-17: 105-0605-0905-1405-17
Signal classification3 categories
Disclosure
571.4%
General
114.3%
Patch
114.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-061
Disclosure1
2026-05-091
Disclosure1
2026-05-144
Disclosure3General1
2026-05-171
Patch1
Full discourse7 posts
  • elhacker.NET@elhackernet
    Disclosure

    Vulnerabilidades en Eclipse BaSyx V2 [https://www.cve.org/CVERecord?id=CVE-2026-7411] Se han divulgado dos vulnerabilidades de seguridad en Eclipse BaSyx V2 que representan un riesgo grave para los entornos industriales. Las vulnerabilidades en cuestión son CVE-2026-7411 [https://www.cve.org/CVERecord?id=CVE-2026-7411] (puntuación CVSS: 10.0), y CVE-2026-7412 [https://nvd.nist.gov/vuln/detail/CVE-2026-7412] (puntuación CVSS: 8.6), un fallo de SSRF

    Post summary

    This entry announces the discovery of two severe SSRF vulnerabilities (CVE-2026-7411 and CVE-2026-7412) in Eclipse BaSyx V2, highlighting their high CVSS scores and industrial risk.

    010821.5K
    140.9K followersView on X
  • NCIIPC India@NCIIPC
    Disclosure

    Remote code execution (#RCE) Vulnerability discovered in #Eclipse BaSyx Java Server SDK versions. Follow OEM Security Advisory to remain safe! #CVE-2026-7411 https://nvd.nist.gov/vuln/detail/CVE-2026-7411

    Post summary

    The tweet announces a newly discovered Remote Code Execution vulnerability in Eclipse BaSyx Java Server SDK versions and encourages users to follow the OEM Security Advisory for mitigation.

    00021408
    8.5K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    References CVE: CVE-2026-7411 CVSS: 10 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text discloses a critical advisory for CVE-2026-7411, providing its CVSS score and severity level, but offers no further technical, exploit, or mitigation details.

    1000044
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-7411 (CVSS 10) — multiple products. CVE: CVE-2026-7411 CVSS: 10 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces a critical vulnerability, CVE‑2026‑7411, providing its CVSS score and severity, but offers no further technical, exploit, or mitigation details.

    1000039
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-7411 CVSS: 10 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequate path normalization in the Submodel HTTP API allows an…

    Post summary

    An advisory has been released for CVE-2026-7411 affecting Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10 due to inadequate path normalization, allowing potentially critical exploits. No PoC, exploit code, patch, or active exploitation is reported.

    1000053
    210 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    A critical path traversal vulnerability (CVE-2026-7411) affects Eclipse BaSyx Java Server SDK before 2.0.0-milestone-10. If you use this SDK, update promptly to prevent unauthorized file writes and potential system compromise. #cybersecurity

    Post summary

    The post announces a path‑traversal flaw in Eclipse BaSyx Java Server SDK and urges users to apply the available patch to prevent potential file‑write exploits.

    0000057
    80 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-7411-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The tweet merely links to a research article about CVE-2026-7411 without providing additional details or evidence of exploitation, patching, or PoC.

    0000025
    210 followersView on X

Explore more