File Path Traversal Vulnerability in Eclipse SW360
CVE-2026-79653

6MEDIUM

Key Information:

Vendor
CVE Published:
27 August 2026

What is CVE-2026-79653?

CVE-2026-79653 is a file path traversal vulnerability found in the Eclipse SW360, an open-source software management tool used for tracking component licenses and vulnerabilities. This vulnerability arises from improper handling of file names during uploads when the system is configured to store attachments in the file system. Specifically, if the enable.attachment.store.to.file.system configuration key is enabled, an attacker can manipulate uploaded filenames, allowing for potential access to unauthorized directories within the system. This exploitation could lead to significant data exposure or integrity issues, as it allows attackers to operate outside of the intended file structure and access sensitive data.

Potential impact of CVE-2026-79653

  1. Data Exposure: Attackers exploiting this vulnerability can traverse directories and access files that should be restricted, potentially exposing sensitive information and adversely affecting data confidentiality.

  2. System Integrity Compromise: By manipulating file paths, attackers could overwrite or alter critical files, leading to issues with software integrity, application behavior, and overall system functionality.

  3. Increased Attack Surface: The existence of this vulnerability expands the attack vectors available to malicious actors, making it easier to launch further attacks or to pivot to additional parts of the network, thereby increasing the risk of broader system compromise.

Affected Version(s)

Eclipse SW360 19.0.0 <= 19.2.0

Eclipse SW360 20.0.0 < 20.0.1

Eclipse SW360 20.1.0 < 20.1.1

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ezinne Kalu
.