CVE-2026-7412Disclosure

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, the Operation Delegation feature fails to validate the destination URI of delegated requests. An unauthenticated remote attacker can exploit this design flaw to force the BaSyx server to execute blind HTTP POST requests to arbitrary internal or external targets. This allows an attacker to bypass network segmentation and pivot into isolated internal IT/OT infrastructure or target Cloud Metadata services (IMDS).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-09: 1Technical Details · 2026-05-09: 105-09
Signal classification1 categories
Disclosure
1100.0%
Referenced assets2 URLs
Full discourse1 post
  • elhacker.NET@elhackernet
    Disclosure

    Vulnerabilidades en Eclipse BaSyx V2 [https://www.cve.org/CVERecord?id=CVE-2026-7411] Se han divulgado dos vulnerabilidades de seguridad en Eclipse BaSyx V2 que representan un riesgo grave para los entornos industriales. Las vulnerabilidades en cuestión son CVE-2026-7411 [https://www.cve.org/CVERecord?id=CVE-2026-7411] (puntuación CVSS: 10.0), y CVE-2026-7412 [https://nvd.nist.gov/vuln/detail/CVE-2026-7412] (puntuación CVSS: 8.6), un fallo de SSRF

    Post summary

    A new set of high‑severity SSRF vulnerabilities (CVE‑2026‑7411 and CVE‑2026‑7412) were disclosed in Eclipse BaSyx V2, with CVSS scores of 10.0 and 8.6, highlighting a serious risk to industrial environments.

    010821.5K
    140.9K followersView on X

Explore more