Authorization Header Exposure in Eclipse BaSyx AAS Web UI
CVE-2026-101322
8.3HIGH
What is CVE-2026-101322?
A vulnerability exists in Eclipse BaSyx AAS Web UI versions v2-241220 and earlier that improperly handles the outgoing requests by attaching the selected infrastructure's Authorization header without verifying the destination origin. This imperfection allows attackers to craft malicious links that, when opened by a user, lead to the user's browser inadvertently sending their Basic Authentication credentials, Bearer tokens, or OAuth2 access tokens to an unauthorized endpoint. By compromising this information, an attacker can gain unauthorized access to protected AAS services while masquerading as the victim. This vulnerability has been resolved in the v2-260924 update.
Affected Version(s)
Eclipse BaSyx AAS Web UI v2-241220
