Arbitrary File Write Vulnerability in Eclipse Embedded CDT by Eclipse
CVE-2026-78299

Currently unrated

What is CVE-2026-78299?

In certain versions of Eclipse Embedded CDT, a vulnerability exists that allows the extraction of compromised CMSIS-Pack archives to write files outside the designated areas of the pack. This can lead to unauthorized file modifications on the disk, posing significant risks to system integrity and security.

Affected Version(s)

Eclipse Embedded CDT (C/C++ Development Tools) 6.0.0 < 6.8.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Eclipse Foundation Security Team
.