PatchDay Alert

CVE

CVE-2026-7411

0field notes · 1digest CVSS 10.0


Daily digests

An unauthenticated attacker can upload files to any location on the filesystem by abusing a path traversal bug in the Eclipse BaSyx Java Server SDK's Submodel HTTP API. A crafted fileName parameter during file upload lets the attacker write outside the intended directory, which leads directly to remote code execution. This is a CVSS 10.0: no authentication, no user interaction, full system compromise.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.