CVE-2026-78299
CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
0th
In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on disk.
| CWE | CWE-22 |
| Vendor | eclipse foundation |
| Product | eclipse embedded cdt (c/c++ development tools) |
| Published | Sep 14, 2026 |
| Last Updated | Sep 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for eclipse foundation eclipse embedded cdt (c/c++ development tools)
Be the first to know when new critical vulnerabilities affecting eclipse foundation eclipse embedded cdt (c/c++ development tools) are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Eclipse Foundation / Eclipse Embedded CDT (C/C++ Development Tools)
6.0.0 < 6.8.0
References
Credits
Eclipse Foundation Security Team