Eclipse Equinox OSGi versions 3.8 through 3.18 contain a...
Critical severity
Unreviewed
Published
May 5, 2026
to the GitHub Advisory Database
•
Updated May 5, 2026
Description
Published by the National Vulnerability Database
May 5, 2026
Published to the GitHub Advisory Database
May 5, 2026
Last updated
May 5, 2026
Eclipse Equinox OSGi versions 3.8 through 3.18 contain a remote code execution vulnerability in the console interface that allows unauthenticated attackers to execute arbitrary code by exploiting the fork command functionality. Attackers can establish a telnet connection to the OSGi console, perform a telnet handshake, and send fork commands to download and execute malicious Java code, establishing a reverse shell connection.
References