Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-78299: Eclipse Embedded CDT can write files anywhere via malicious pack

CVE-2026-78299 · published 26 days ago
Summary

Versions 6.0 through 6.7 of Eclipse Embedded CDT may extract a specially crafted CMSIS pack and place files outside the intended folder. This could let an attacker create or overwrite any file on the computer, potentially taking control of the system. Update to a newer version of Eclipse Embedded CDT or use only trusted CMSIS packs to mitigate the risk.

What to do
  • Update eclipse foundation eclipse embedded cdt (c/c++ development tools) to version 6.8.0 or later.
Affected software
VendorProductAffected versions
eclipse foundation eclipse embedded cdt (c/c++ development tools) < 6.8.0
Original advisory text
In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing o...
In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on disk.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-22Path Traversal
Timeline
Published14 Sep 2026
Updated7 Oct 2026
First seen14 Sep 2026
Sources
CVE-2026-78299 · MITRE
Track software like this
Free during beta