Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-101322

Quick assessment

Affected
Eclipse Foundation Eclipse BaSyx AAS Web UI
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Eclipse BaSyx AAS Web UI 的 v2-241220 至 v2-260924 之前的版本中,共享的请求处理程序在发出请求时,会将所选基础设施的 头附加到出站请求中,而未检查目标来源(origin)。在启用身份验证的部署环境中,攻击者可以诱导用户打开一个精心构造的 Web UI 链接,该链接中的 或 查询参数指向攻击者控制的端点。随后,用户的浏览器会将已配置的基本认证凭据、Bearer 令牌或可用的 OAuth2 访问令牌发送至该端点。攻击者可利用泄露的凭据,以受害者的权限访问受保护的 AAS

CVSS 8.3 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-101322

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
In Eclipse BaSyx AAS Web UI versions v2-241220 through releases before v2-260924, the shared request handler attached the selected infrastructure's `Authorization` header to outgoing requests without checking the destination origin. In deployments using authentication, an attacker could induce a user to open a crafted Web UI link whose `aas` or `path` query parameter points to an attacker-controlled endpoint. The user's browser would then send the configured Basic Authentication credentials, Bearer token, or an available OAuth2 access token to that endpoint. The attacker could reuse the disclosed credential to access protected AAS services with the victim's privileges. The issue is fixed in v2-260924.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过发送数据的信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Eclipse Foundation Eclipse BaSyx AAS Web UI v2-241220 ~ v2-260924 -

II. Public POCs for CVE-2026-101322

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-101322

请登录查看更多情报信息。

Other References for CVE-2026-101322 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-101322

No comments yet


Leave a comment