CVE-2026-7412 PUBLISHED

Assigner: eclipse
Reserved: 29.04.2026 Published: 05.05.2026 Updated: 05.05.2026

In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, the Operation Delegation feature fails to validate the destination URI of delegated requests. An unauthenticated remote attacker can exploit this design flaw to force the BaSyx server to execute blind HTTP POST requests to arbitrary internal or external targets. This allows an attacker to bypass network segmentation and pivot into isolated internal IT/OT infrastructure or target Cloud Metadata services (IMDS).

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CVSS Score: 8.6

Product Status

Vendor Eclipse Foundation
Product Eclipse BaSyx
Versions Default: unaffected
  • affected from 0 to 2.0.0-milestone-10 (excl.)

Credits

  • Mohamed Lemine Ahmed Jidou (AegisSec) finder

References

Problem Types

  • CWE-918 Server-Side request forgery (SSRF) CWE