CVE-2026-101322
Received Received - Intake

Authorization Header Exposure in Eclipse BaSyx AAS Web UI

Vulnerability report for CVE-2026-101322, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Eclipse Foundation

Description

In Eclipse BaSyx AAS Web UI versions v2-241220 through releases before v2-260924, the shared request handler attached the selected infrastructure's `Authorization` header to outgoing requests without checking the destination origin. In deployments using authentication, an attacker could induce a user to open a crafted Web UI link whose `aas` or `path` query parameter points to an attacker-controlled endpoint. The user's browser would then send the configured Basic Authentication credentials, Bearer token, or an available OAuth2 access token to that endpoint. The attacker could reuse the disclosed credential to access protected AAS services with the victim's privileges. The issue is fixed in v2-260924.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
eclipse basyx_aas_web_ui From 2-241220 (inc) to 2-260924 (exc)
eclipse basyx_aas_web_ui 2-260924

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-201 The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Eclipse BaSyx AAS Web UI versions between v2-241220 and before v2-260924. The shared request handler sends the infrastructure's Authorization header to any destination without checking the origin. Attackers can craft links with malicious endpoints in query parameters. When a user opens such a link, their browser sends authentication credentials to the attacker's endpoint.

Detection Guidance

Check if your Eclipse BaSyx AAS Web UI version is between v2-241220 and before v2-260924. Review web server logs for unusual requests to external endpoints via crafted links with aas or path parameters. Monitor for unauthorized access attempts to AAS services using disclosed credentials.

Impact Analysis

An attacker could steal your authentication credentials (Basic Auth, Bearer tokens, OAuth2 tokens) and use them to access protected AAS services with your privileges. This could lead to unauthorized data access, manipulation, or service disruption in systems using the vulnerable BaSyx Web UI versions.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. It may result in data breaches, non-compliance with access control policies, and potential legal penalties for organizations failing to protect personal or health information.

Mitigation Strategies

Upgrade to Eclipse BaSyx AAS Web UI version v2-260924 or later immediately. Review and restrict trusted origins in the YAML configuration. Audit and revoke any potentially exposed credentials. Monitor for suspicious activity in AAS services.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101322. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart