๐Ÿ” CVE Alert

CVE-2026-79653

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In Eclipse SW360 versions 19.0.0, 19.1.0, 19.2.0, 20.0.0, 20.1.0, if the system is configured to use file system storage with config key enable.attachment.store.to.file.system, the attacker can manipulate the filename upon upload and can essentially cause arbitrary file path traversal. The immediate workaround is to disable enable.attachment.store.to.file.system or update to fixed versions.

CWE CWE-22 CWE-73
Vendor eclipse foundation
Product eclipse sw360
Published Aug 27, 2026
Last Updated Aug 27, 2026
Stay Ahead of the Next One

Get instant alerts for eclipse foundation eclipse sw360

Be the first to know when new unknown vulnerabilities affecting eclipse foundation eclipse sw360 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Eclipse Foundation / Eclipse SW360
19.0.0 โ‰ค 19.2.0 20.0.0 < 20.0.1 20.1.0 < 20.1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
gitlab.eclipse.org: https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/765 github.com: https://github.com/eclipse-sw360/sw360/pull/4518 github.com: https://github.com/eclipse-sw360/sw360/pull/4517 github.com: https://github.com/eclipse-sw360/sw360/pull/4516

Credits

๐Ÿ” Ezinne Kalu