CVE-2026-79653
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
In Eclipse SW360 versions 19.0.0, 19.1.0, 19.2.0, 20.0.0, 20.1.0, if the system is configured to use file system storage with config key enable.attachment.store.to.file.system, the attacker can manipulate the filename upon upload and can essentially cause arbitrary file path traversal. The immediate workaround is to disable enable.attachment.store.to.file.system or update to fixed versions.
| CWE | CWE-22 CWE-73 |
| Vendor | eclipse foundation |
| Product | eclipse sw360 |
| Published | Aug 27, 2026 |
| Last Updated | Aug 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for eclipse foundation eclipse sw360
Be the first to know when new unknown vulnerabilities affecting eclipse foundation eclipse sw360 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Eclipse Foundation / Eclipse SW360
19.0.0 โค 19.2.0 20.0.0 < 20.0.1 20.1.0 < 20.1.1
References
Credits
๐ Ezinne Kalu