File Overwrite Vulnerability in Apache Ant Affects Remote File Downloading
CVE-2026-78254

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
7 September 2026

What is CVE-2026-78254?

Apache Ant has a security vulnerability in its FTP and SCP tasks that allows malicious servers to provide relative paths, enabling them to write files outside of the designated target directory. This can lead to unauthorized file overwrites under the permissions of the user executing Ant. Exploitation requires either a malicious server or a man-in-the-middle attack. To mitigate risks, users should ensure that server identity checks are not bypassed, and those using FTP are encouraged to switch to FTPS. Upgrading to Apache Ant version 1.10.18 or higher is recommended to protect against this vulnerability.

Affected Version(s)

Apache Ant 1.2 < 1.10.18

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.