Authorization Header Exposure in Eclipse BaSyx AAS Web UI
CVE-2026-101322

8.3HIGH

Key Information:

Vendor
CVE Published:
1 October 2026

What is CVE-2026-101322?

A vulnerability exists in Eclipse BaSyx AAS Web UI versions v2-241220 and earlier that improperly handles the outgoing requests by attaching the selected infrastructure's Authorization header without verifying the destination origin. This imperfection allows attackers to craft malicious links that, when opened by a user, lead to the user's browser inadvertently sending their Basic Authentication credentials, Bearer tokens, or OAuth2 access tokens to an unauthorized endpoint. By compromising this information, an attacker can gain unauthorized access to protected AAS services while masquerading as the victim. This vulnerability has been resolved in the v2-260924 update.

Affected Version(s)

Eclipse BaSyx AAS Web UI v2-241220

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Eclipse Foundation Security Team
.