


Perceptive Security
SOC/SIEM Consultancy

Eclipse Equinox OSGi versions 3.8 through 3.18 contain a remote code execution vulnerability in the console interface that allows unauthenticated attackers to e…
Published:
4 mei 2026 om 22:00:00
Alert date:
5 mei 2026 om 13:07:56
Source:
nvd.nist.gov
Enterprise Applications, Web Technologies
Eclipse Equinox OSGi versions 3.8 through 3.18 contain a critical remote code execution vulnerability in the console interface. The vulnerability allows unauthenticated attackers to execute arbitrary code by exploiting the fork command functionality through telnet connections. Attackers can establish connections to the OSGi console, perform handshakes, and send fork commands to download and execute malicious Java code. This exploitation method enables attackers to establish reverse shell connections, providing complete system compromise. The vulnerability affects a wide range of versions spanning multiple years of releases.
Technical details
Mitigation steps:
Affected products:
Eclipse Equinox OSGi
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2023-54342
https://www.exploit-db.com/exploits/51878
https://www.vulncheck.com/advisories/eclipse-equinox-osgi-console-remote-code-execution
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
