Description
In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on disk.
Published: 2026-09-14
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Write
Action: Patch ASAP
AI Analysis

Impact

The flaw allows an attacker to extract a compromised CMSIS‑Pack archive in Eclipse Embedded CDT versions 6.0–6.7 to write arbitrary files outside the intended extraction directory. This arbitrary file write (CWE-22) could overwrite critical system or IDE files, inject malicious binaries, or modify build configurations, exposing the system to potential code execution or data exfiltration. The vulnerability arises from insufficient path validation during archive extraction.

Affected Systems

Eclipse Foundation’s Eclipse Embedded CDT (6.0 through 6.7 contain the flaw, allowing the extraction of CMSIS‑Pack archives to write files outside the intended workspace directory. The vulnerability is not listed in CISA KEV.

Risk and Exploitability

The EPSS score of <1% indicates a low but non‑zero likelihood of exploitation, and the CVSS base score is 9.1, reflecting high severity due to arbitrary file write. While no public exploits are documented, the vulnerability allows an attacker who supplies a malicious CMSIS‑Pack and triggers its extraction within the IDE to overwrite files outside the intended directory. This capability can potentially replace critical workspace or system files, leading to code execution or data compromise. Based on the description, it is inferred that the likely attack vector involves local or privileged access to the IDE to trigger extraction, but a remote attacker might leverage the vulnerability if they can gain IDE access. Thus the risk depends on user privileges and access method.

Generated by OpenCVE AI on September 21, 2026 at 01:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Eclipse Embedded CDT 6.8 or newer to eliminate the extraction flaw.
  • If upgrade is not possible, do not import untrusted CMSIS packs; verify checksums or signatures before extraction.
  • Restrict file system permissions for the Eclipse IDE workspace to prevent arbitrary writes; run the IDE under a user with limited privileges.

Generated by OpenCVE AI on September 21, 2026 at 01:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Title E-Pack Extraction

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Eclipse
Eclipse eclipse Embedded Cdt
Vendors & Products Eclipse
Eclipse eclipse Embedded Cdt

Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Title E-Pack Extraction

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on disk.
Weaknesses CWE-22
References

Subscriptions

Eclipse Eclipse Embedded Cdt
cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2026-09-14T19:23:10.801Z

Reserved: 2026-08-24T07:49:18.635Z

Link: CVE-2026-78299

cve-icon Vulnrichment

Updated: 2026-09-14T19:23:05.575Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T13:18:46.870

Modified: 2026-09-16T20:38:33.883

Link: CVE-2026-78299

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:30:08Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')