CVE-2026-101322: High severity Eclipse BaSyx AAS Web UI vulnerability

Published Oct 1, 2026
·
Updated

In Eclipse BaSyx AAS Web UI versions v2-241220 through releases before v2-260924, the shared request handler attached the selected infrastructure's Authorization header to outgoing requests without checking the destination origin. In deployments using authentication, an attacker could induce a user to open a crafted Web UI link whose aas or path query parameter points to an attacker-controlled endpoint. The user's browser would then send the configured Basic Authentication credentials, Bearer token, or an available OAuth2 access token to that endpoint. The attacker could reuse the disclosed credential to access protected AAS services with the victim's privileges. The issue is fixed in v2-260924.

Affected Software

1 affected component
Eclipse BaSyx AAS Web UI>=v2-241220<v2-260924

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Eclipse BaSyx AAS Web UI to a version that resolves this vulnerability.

    Fixed in v2-260924

Event History

Oct 1, 2026
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to credential disclosure?

Deployments of the affected Web UI versions that use authentication are exposed when a user opens a crafted link. The disclosed credential may be Basic Authentication credentials, a Bearer token, or an OAuth2 access token available to the user's browser session.

2

What does an attacker need to exploit this issue?

The attacker needs to induce a user to open a crafted Web UI URL with an aas or path query parameter directed at an attacker-controlled endpoint. Exploitation relies on the victim's browser having access to credentials configured for the selected infrastructure.

3

What can be done if upgrading is not immediately possible?

Prevent users from opening untrusted Web UI links, especially links containing aas or path query parameters, and restrict access to the Web UI where possible. Upgrading to v2-260924 removes the vulnerable request-handler behavior.

4

How can I determine whether my instance is affected?

Instances running v2-241220 through versions before v2-260924 are affected. Review whether the Web UI is configured to use Basic Authentication, Bearer tokens, or OAuth2, as these credentials can be sent to an attacker-controlled destination through crafted links.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203