CVE-2026-15704
A flaw in Eclipse BaSyx Go Components lets attackers bypass access control by adding a trailing slash to protected URLs. The bug occurs because the router removes the slash before the ABAC middleware checks permissions, allowing unauthorized actions. It affects all ABAC‑enabled services that use the shared router.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Eclipse BaSyx Go Components versions 1.0.0 and earlier that are ABAC‑enabled, including AAS Repository, Submodel Repository, AAS Registry, Submodel Registry, Concept Description Repository, Discovery, and AAS Environment upload services.
Real-world impact
An attacker who can reach the API can read, create, update, delete, or upload data that should be protected, effectively taking full control over the affected resources.
Why this severity
The CVSS score of 9.8 reflects that the flaw is network‑exposed, requires no authentication, and gives an attacker complete control over confidentiality, integrity, and availability of the protected data.
What to do about it
- 01Upgrade Eclipse BaSyx Go Components to version 1.0.1 or later.
- 02Restart the affected services to apply the update.
NVD-referenced vendor advisory
Timeline
- Jul 24, 2026 · 8d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 8d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 30, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.