Junglewise Threat Intelligence

CVE-2026-15704: Eclipse BaSyx Go Components ABAC authorization bypass via trailing slash

CVE-2026-15704 · Severity: critical · CVSS 9.8 · Published 2026-07-24

Vendors: Eclipse Foundation.

Executive brief

Eclipse BaSyx Go Components, used for managing digital twins and industrial data, contains a security flaw in its access control system. An attacker can bypass security checks by simply adding a trailing slash to a web address (URL). This could allow unauthorized users to view, modify, or delete sensitive industrial data and configuration files.

Technical details

An authorization bypass exists in Eclipse BaSyx Go Components due to a discrepancy in how the ABAC middleware and the Chi HTTP router handle trailing slashes (CWE-180). The router was configured with 'middleware.StripSlashes', which normalized paths like '/shells/' to '/shells' before execution. However, the ABAC middleware evaluated the original path with the trailing slash; if it failed to find a matching policy for the slash-suffixed path, it permitted the request to proceed to the router. An unauthenticated remote attacker can exploit this by appending a '/' to API routes, bypassing ABAC policy enforcement and query filters. This affects multiple services including AAS and Submodel Repositories/Registries. The issue is resolved in version 1.0.1.

Affected products

  • Eclipse Foundation BaSyx Go Components <= 1.0.0

Timeline

  • 2026-07-03: patched: Fix merged in pull request #442 and released in v1.0.1
  • 2026-07-24: disclosed: CVE-2026-15704 published

References