Description
In Eclipse BaSyx AAS Web UI versions v2-241220 through releases before v2-260924, the shared request handler attached the selected infrastructure's `Authorization` header to outgoing requests without checking the destination origin. In deployments using authentication, an attacker could induce a user to open a crafted Web UI link whose `aas` or `path` query parameter points to an attacker-controlled endpoint. The user's browser would then send the configured Basic Authentication credentials, Bearer token, or an available OAuth2 access token to that endpoint. The attacker could reuse the disclosed credential to access protected AAS services with the victim's privileges. The issue is fixed in v2-260924.
Published: 2026-10-01
Score: 8.3 High
EPSS: n/a
KEV: No
Impact: Credential Leakage and Unauthorized Access
Action: Immediate Patch
AI Analysis

Impact

The Eclipse BaSyx AAS Web UI at versions v2‑241220 through just before v2‑260924 contains a request handler that indiscriminately forwards the selected infrastructure's Authorization header to any destination accessed via the "aas" or "path" query parameters. This behavior constitutes a CWE‑201 weakness: unauthorized disclosure of credentials over an insecure channel. An attacker can construct a fabricated Web UI link that points to an external, attacker‑controlled endpoint; when the victim's browser follows the link the Basic Authentication, Bearer token, or OAuth2 access token is sent unfiltered. The attacker obtains these credentials and can subsequently access protected Asset Administration Shell services with the victim’s privileges, leading to credential leakage and unauthorized access.

Affected Systems

The affected product is the Eclipse Foundation’s BaSyx AAS Web UI. Vulnerable releases span from v2‑241220 up to, but not including, v2‑260924. The bug was addressed in the v2‑260924 release. The issue applies only to deployments that enable authentication, as the forwarded header contains user credentials.

Risk and Exploitability

The CVSS score of 8.3 classifies this as high severity. No EPSS score has been published, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires minimal effort—an attacker must convince a user to click a malicious link, a low‑barrier social‑engineering technique. Once the request includes the victim’s Authorization header, the attacker immediately receives the token or credentials and can access any AAS resources the user is authorized for. The likelihood of exploitation is therefore significant, especially in environments with wide user bases and no additional monitoring of outgoing requests.

Generated by OpenCVE AI on October 1, 2026 at 18:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Eclipse BaSyx AAS Web UI to version v2‑260924 or later, where the request handler no longer forwards the Authorization header to untrusted destinations.
  • Restrict cross‑origin traffic by configuring CORS policies in the web UI to disallow requests from external domains.
  • Validate or sanitize the "aas" and "path" query parameters to refuse external URLs, preventing the creation of malicious redirects.

Generated by OpenCVE AI on October 1, 2026 at 18:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 18:45:00 +0000

Type Values Removed Values Added
Title Authorization Header Leakage via Unvalidated Redirection in BaSyx AAS Web UI

Thu, 01 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 16:15:00 +0000

Type Values Removed Values Added
Description In Eclipse BaSyx AAS Web UI versions v2-241220 through releases before v2-260924, the shared request handler attached the selected infrastructure's `Authorization` header to outgoing requests without checking the destination origin. In deployments using authentication, an attacker could induce a user to open a crafted Web UI link whose `aas` or `path` query parameter points to an attacker-controlled endpoint. The user's browser would then send the configured Basic Authentication credentials, Bearer token, or an available OAuth2 access token to that endpoint. The attacker could reuse the disclosed credential to access protected AAS services with the victim's privileges. The issue is fixed in v2-260924.
Weaknesses CWE-201
References
Metrics cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2026-10-01T16:15:41.152Z

Reserved: 2026-09-28T13:44:59.870Z

Link: CVE-2026-101322

cve-icon Vulnrichment

Updated: 2026-10-01T16:15:38.205Z

cve-icon NVD

Status : Received

Published: 2026-10-01T16:17:32.587

Modified: 2026-10-01T17:17:17.330

Link: CVE-2026-101322

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T18:30:11Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data