Summary
CVE-2026-57898 is a critical unauthenticated arbitrary file write vulnerability (CWE-22 / CWE-73) in the Eclipse BaSyx Java Server SDK, affecting deployments that use the MongoDB backend across versions 2.0.0-milestone-05 through 2.0.0-milestone-12. By supplying a crafted fileName parameter to the AAS thumbnail API, a remote unauthenticated attacker can write arbitrary file content to any location the Java process has permission to access — a condition that may lead to remote code execution. The vulnerability carries a CVSS v3.1 base score of 9.0 (Critical).
Technical details
- Root cause: The AAS thumbnail upload endpoint accepted a client-controlled
fileNamerequest parameter and passed it directly through file repository handling as both a GridFS key and a local filesystem path. With the MongoDB backend, the supplied filename was stored as an opaque GridFS key and was never normalized or restricted to a safe base directory. - Trigger conditions: An attacker sends a thumbnail upload request with an absolute path or path traversal sequence (e.g.,
../../) as thefileNamevalue. A subsequent thumbnail retrieval request causes the server to write the previously uploaded bytes to the attacker-controlled filesystem path. - Attack vector: Fully remote and unauthenticated — no credentials, session tokens, or user interaction are required. The attack is conducted entirely over the network via the HTTP REST API exposed by the server.
- Impact: An attacker can write arbitrary files to any location the Java process can reach on the underlying host. The Eclipse Foundation’s own advisory explicitly states this condition "may lead to remote code execution." The vulnerability carries a Scope:Changed rating (S:C), reflecting the potential for impact beyond the vulnerable component itself. Confidentiality, integrity, and availability are all rated High.
- Unaffected configuration: The default InMemory backend is not affected, because it normalizes and restricts file paths to its own temporary directory.
Affected software
- Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 through 2.0.0-milestone-12, when deployed with the MongoDB backend.
- The default InMemory backend configuration is not affected.
Severity
- CVSS v3.1 Base Score: 9.0 (Critical)
- Vector String:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Mitigation and recommended actions
- Patch immediately: Upgrade to Eclipse BaSyx Java Server SDK 2.0.0-milestone-13, which secures repository file paths and stream downloads to prevent path traversal exploitation. The fix was introduced in pull request #1024 and is available in the milestone-13 release on GitHub.
- If immediate patching is not possible:
- Avoid deploying the MongoDB backend in internet-exposed configurations until the patch is applied. Switching to the default InMemory backend eliminates this specific attack path.
- Enforce strict network-layer access controls to restrict who can send requests to the AAS thumbnail API endpoints. Only trusted internal hosts should be permitted to reach these endpoints.
- Monitor for unexpected file creation activity in directories accessible to the Java server process.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

