← All Advisories

CVE-2026-101322

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-101322

Key Details

CVECVE-2026-101322
CVSS Score / Version8.3 (High) / CVSS v4.0
Updated2026-10-01
Affected productsEclipse Foundation Eclipse BaSyx AAS Web UI
Classified asCWE-201 (Insertion of Sensitive Information Into Sent Data)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Eclipse FoundationEclipse BaSyx AAS Web UI
SubsystemsGeneral OT
SectorsMultiple

What to Know

In Eclipse BaSyx AAS Web UI versions v2-241220 through releases before v2-260924, the shared request handler attached the selected infrastructure's `Authorization` header to outgoing requests without checking the destination origin. In deployments using authentication, an attacker could induce a user to open a crafted Web UI link whose `aas` or `path` query parameter points to an attacker-controlled endpoint. The user's browser would then send the configured Basic Authentication credentials, Bearer token, or an available OAuth2 access token to that endpoint. The attacker could reuse the disclosed credential to access protected AAS services with the victim's privileges. The issue is fixed in v2-260924. (NVD)

What to Do

Monitor Eclipse Foundation's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-101322
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-101322